Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.62%—Oretnom23 Employee AND Visitor Gate Pass Logging System12/6/202417/6/2026
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scripting. The attack can…
ModificadaMedia (6.9)0.68%—Oretnom23 Employee AND Visitor Gate Pass Logging System12/6/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaMedia (5.3)0.61%—Oretnom23 Employee AND Visitor Gate Pass Logging System12/6/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.…
AnalizadaMedia (4.9)0.41%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
AnalizadaBaja (2.7)0.27%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
AplazadaMedia (5.9)0.25%—Universal Passport RXAI3/6/202417/6/2026
Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product.
AplazadaMedia (6.5)0.29%—Universal Passport RXAI3/6/202417/6/2026
Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.
AplazadaMedia (5.6)0.11%—Hypr PasswordlessAI21/5/202417/6/2026
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
AnalizadaMedia (6.5)0.70%💥 PoCKeepassxc20/5/202417/6/2026
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
AnalizadaMedia (6.5)0.34%—Keepassxc20/5/202417/6/2026
KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.
AplazadaAlta (7.8)0.72%—Watchguard Authpoint Password ManagerAI16/5/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for…
AnalizadaMedia (5.3)0.67%—Oretnom23 Employee AND Visitor Gate Pass Logging System16/5/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack…
AplazadaMedia (4.3)0.34%—Wpexperts Password ProtectedAI15/5/202417/6/2026
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract…
AplazadaAlta (7.5)0.57%—Counterpane PasswordsafeAI6/5/202417/6/2026
Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.
AnalizadaMedia (4.3)0.48%—Passbolt API26/4/202417/6/2026
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of…
AnalizadaMedia (6.8)0.64%—Passbolt Browser Extension26/4/202417/6/2026
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords…
AnalizadaMedia (6.8)0.23%—Mongodb Compass24/4/202417/6/2026
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
AplazadaAlta (7.1)0.33%—Jojaba Access Category PasswordAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jojaba Access Category Password allows Reflected XSS.This issue affects Access Category Password: from n/a through 1.5.1.
AnalizadaMedia (6.1)0.41%—Netvision Airpass15/4/202417/6/2026
The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
AnalizadaAlta (8.8)0.57%—Enpass Password Manager10/4/202417/6/2026
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
ModificadaMedia (5.4)0.50%—Wpchill Passster9/4/202417/6/2026
The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaMedia (6.1)0.23%—Wpassist Countdown Widget27/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPress Countdown Widget: from n/a through 3.1.9.1.
AplazadaBaja (2.2)0.09%—Kaspersky Password ManagerAIGoogle ChromeAI22/3/202417/6/2026
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the…
AnalizadaAlta (7.1)0.24%—Itopvpn Dualsafe Password Manager21/3/202417/6/2026
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.
AplazadaMedia (6.5)0.33%—Cozmoslabs Passwordless LoginAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.
Orbitaley — Vulnerabilidades