Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Cyber-ark Password Vault WEB Access | 5/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cyber-Ark Password Vault Web Access (PVWA) 5.0 and earlier, 5.5 through 5.5 patch 4, and 6.0 through 6.0 patch 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.30% | — | Martinicreations Passmanlite Password Manager | 13/5/2011 | 16/6/2026 | The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access. | |
| Modificada | Media (6.2) | 0.77% | — | Oracle Passlogix V-go Self-service Password Reset AND OEM | 7/2/2011 | 16/6/2026 | Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is… | |
| Modificada | Alta (7.2) | 0.75% | 💥 Exploit | Tukeva Password Reminder | 21/4/2010 | 16/6/2026 | TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. | |
| Modificada | Alta (7.5) | 1.1% | — | Robert Heel CWT Resetbepassword | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Manageengine Password Manager PROManageengine Password Manager Pro6.1 | 22/12/2009 | 16/6/2026 | The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Yellowswordfish Simple Forum | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Ascadnetworks Password Protector SD | 8/6/2009 | 16/6/2026 | Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative access by setting the (1) c7portal and (2) cookname cookies to "admin." | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Wholehogsoftware Password Protect | 10/2/2009 | 16/6/2026 | Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Wholehogsoftware Password Protect | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 29% | 💥 Exploit | Cisco ACS FOR WindowsCisco ACS Solution EngineCisco User Changeable Password | 14/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the… | |
| Modificada | Alta (10) | 57% | 💥 Exploit | Cisco ACS FOR WindowsCisco ACS Solution EngineCisco User Changeable Password | 14/3/2008 | 16/6/2026 | Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly… | |
| Modificada | Alta (7.5) | 2.9% | — | THE Sword Project Diatheke Front ENDTHE Sword Project Sword | 25/2/2008 | 16/6/2026 | diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Glossword | 17/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter. | |
| Modificada | Alta (10) | 8.0% | 💥 Exploit | Manageengine Passwordmanager PRO | 2/5/2007 | 16/6/2026 | ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injecting a certain command line for the mysql program, as demonstrated by the "-port 2345" and "-u root" arguments. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Media (6.9) | 0.38% | — | Dreameesoft Password Master | 10/3/2007 | 16/6/2026 | DreameeSoft Password Master 1.0 stores the database in an unencrypted format when the master password is set, which allows attackers with physical access to read the database contents via an unspecified authentication bypass. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Alta (7.5) | 1.8% | — | RBL Tpassword | 6/2/2007 | 16/6/2026 | SQL injection vulnerability in login.asp for tPassword in the Raymond BERTHOU script collection (aka RBL - ASP) allows remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. | |
| Modificada | Media (6.4) | 1.3% | — | IBM Client Security Password Manager | 5/10/2006 | 16/6/2026 | IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page. | |
| Modificada | Baja (2.1) | 0.45% | — | Counterpane Passwordsafe | 28/7/2006 | 16/6/2026 | Password Safe 2.11, 2.16 and 3.0BETA1 does not respect the configuration settings for locking the password database when certain dialogue windows are open, which might allow attackers with physical access to obtain the database contents. | |
| Modificada | Media (4.9) | 0.33% | — | Counterpane Password Safe | 24/3/2006 | 16/6/2026 | PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a… | |
| Modificada | Alta (10) | 1.4% | — | Pear Text Password | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. | |
| Modificada | Media (4.6) | 0.21% | — | Counterpane Passwordsafe | 24/11/2005 | 16/6/2026 | CounterPane PasswordSafe 1.x and 2.x allows local users to test possible encryption keys against a subset of the stored key data without performing the more expensive key derivation function (KDF) function, which reduces the search time in brute force attacks. | |
| Modificada | Alta (7.5) | 2.3% | — | Crosswire Bible Society Sword | 2/5/2005 | 16/6/2026 | diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Alta (7.2) | 0.38% | — | Changepassword | 10/1/2005 | 16/6/2026 | changepassword.cgi in ChangePassword 0.8, when installed setuid, allows local users to execute arbitrary code by modifying the PATH environment variable to point to a malicious "make" program. |