Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.62% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 12/6/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scripting. The attack can… | |
| Modificada | Media (6.9) | 0.68% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 12/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The… | |
| Modificada | Media (5.3) | 0.61% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 12/6/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely.… | |
| Analizada | Media (4.9) | 0.41% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response. | |
| Analizada | Baja (2.7) | 0.27% | — | Beyondtrust Beyondinsight Password Safe | 11/6/2024 | 17/6/2026 | A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request. | |
| Aplazada | Media (5.9) | 0.25% | — | Universal Passport RXAI | 3/6/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product. | |
| Aplazada | Media (6.5) | 0.29% | — | Universal Passport RXAI | 3/6/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product. | |
| Aplazada | Media (5.6) | 0.11% | — | Hypr PasswordlessAI | 21/5/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1. | |
| Analizada | Media (6.5) | 0.70% | 💥 PoC | Keepassxc | 20/5/2024 | 17/6/2026 | Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs. | |
| Analizada | Media (6.5) | 0.34% | — | Keepassxc | 20/5/2024 | 17/6/2026 | KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs. | |
| Aplazada | Alta (7.8) | 0.72% | — | Watchguard Authpoint Password ManagerAI | 16/5/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for… | |
| Analizada | Media (5.3) | 0.67% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 16/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack… | |
| Aplazada | Media (4.3) | 0.34% | — | Wpexperts Password ProtectedAI | 15/5/2024 | 17/6/2026 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract… | |
| Aplazada | Alta (7.5) | 0.57% | — | Counterpane PasswordsafeAI | 6/5/2024 | 17/6/2026 | Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography. | |
| Analizada | Media (4.3) | 0.48% | — | Passbolt API | 26/4/2024 | 17/6/2026 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of… | |
| Analizada | Media (6.8) | 0.64% | — | Passbolt Browser Extension | 26/4/2024 | 17/6/2026 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords… | |
| Analizada | Media (6.8) | 0.23% | — | Mongodb Compass | 24/4/2024 | 17/6/2026 | MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0. | |
| Aplazada | Alta (7.1) | 0.33% | — | Jojaba Access Category PasswordAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jojaba Access Category Password allows Reflected XSS.This issue affects Access Category Password: from n/a through 1.5.1. | |
| Analizada | Media (6.1) | 0.41% | — | Netvision Airpass | 15/4/2024 | 17/6/2026 | The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks. | |
| Analizada | Alta (8.8) | 0.57% | — | Enpass Password Manager | 10/4/2024 | 17/6/2026 | HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note. | |
| Modificada | Media (5.4) | 0.50% | — | Wpchill Passster | 9/4/2024 | 17/6/2026 | The Passster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_protector shortcode in all versions up to, and including, 4.2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.23% | — | Wpassist Countdown Widget | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPress Countdown Widget: from n/a through 3.1.9.1. | |
| Aplazada | Baja (2.2) | 0.09% | — | Kaspersky Password ManagerAIGoogle ChromeAI | 22/3/2024 | 17/6/2026 | Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the… | |
| Analizada | Alta (7.1) | 0.24% | — | Itopvpn Dualsafe Password Manager | 21/3/2024 | 17/6/2026 | An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret. | |
| Aplazada | Media (6.5) | 0.33% | — | Cozmoslabs Passwordless LoginAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2. |