Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 28/9/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated… | |
| Aplazada | Baja (2) | 0.14% | — | Enpass Password ManagerAI | 26/9/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is… | |
| Analizada | Media (4.8) | 0.33% | — | Anujk305 BUS Pass Management System | 13/9/2024 | 17/6/2026 | phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters. | |
| Modificada | Alta (7.1) | 0.44% | — | Profelis Passbox | 9/9/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse. This issue affects PassBox: before v1.2. | |
| Modificada | Media (6.1) | 0.33% | — | Syspass | 3/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php. | |
| Aplazada | Crítica (9.8) | 51% | 💥 Exploit | Oneidentity Safeguard FOR Privileged PasswordsAI | 30/8/2024 | 17/6/2026 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 28/8/2024 | 17/6/2026 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option. | |
| Analizada | Media (6.1) | 0.32% | — | Microfocus Netiq Self Service Password Reset | 21/8/2024 | 17/6/2026 | Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6 | |
| Analizada | Alta (7.8) | 0.31% | — | 1password | 6/8/2024 | 17/6/2026 | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient. | |
| Analizada | Media (4.7) | 0.20% | — | 1password | 6/8/2024 | 17/6/2026 | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms. | |
| Analizada | Alta (8.5) | 0.33% | — | Itopvpn Dualsafe Password Manager | 31/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was… | |
| Modificada | Media (4.9) | 0.34% | — | Arubanetworks Clearpass Policy Manager | 30/7/2024 | 17/6/2026 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by… | |
| Modificada | Media (4.9) | 0.36% | — | Arubanetworks Clearpass Policy Manager | 30/7/2024 | 17/6/2026 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by… | |
| Analizada | Alta (8.8) | 0.55% | — | Arubanetworks Clearpass Policy Manager | 30/7/2024 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying… | |
| Modificada | Media (5.3) | 0.42% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 24/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects some unknown processing of the file /employee_gatepass/classes/Master.php?f=delete_department. The manipulation of the argument id leads to sql injection. The attack… | |
| Modificada | Media (5.3) | 0.45% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 22/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. This affects an unknown part of the file /employee_gatepass/admin/?page=employee/manage_employee. The manipulation of the argument id leads to sql injection. It is possible to initiate the… | |
| Modificada | Media (5.3) | 0.55% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 15/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file view_employee.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Media (5.1) | 0.52% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 10/7/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this issue is the function save_designation of the file /classes/Master.php. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (6.9) | 0.35% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 10/7/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the function save_users of the file Users.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.48% | — | Mongodb Compass | 1/7/2024 | 17/6/2026 | MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2 | |
| Aplazada | Alta (7.2) | 0.59% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands. | |
| Aplazada | Media (4.9) | 0.61% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system. | |
| Aplazada | Baja (3.5) | 0.19% | — | NewpassAI | 29/6/2024 | 17/6/2026 | NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use. | |
| Aplazada | Media (6.5) | 0.31% | — | Clickstudios PasswordstateAI | 24/6/2024 | 17/6/2026 | Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. | |
| Modificada | Media (6.9) | 0.67% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 13/6/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function log_employee of the file /classes/Master.php?f=log_employee. The manipulation of the argument employee_code leads to sql injection. It is possible to launch the… |