Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
ModificadaMedia (4.3)1.3%—WEB Animations Password Protect31/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.
ModificadaAlta (7.5)1.2%💥 ExploitWEB Animations Password Protect30/8/200416/6/2026
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.
ModificadaMedia (5)1.3%—Coffeecup Software Coffeecup Password Wizard31/12/200316/6/2026
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
ModificadaMedia (5)3.5%💥 ExploitCgiscript.net Cspassword4/10/200216/6/2026
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error.
ModificadaMedia (5.1)1.3%—Cgiscript.net Cspassword4/10/200216/6/2026
CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed.
ModificadaAlta (7.5)3.1%💥 ExploitCgiscript.net Cspassword4/10/200216/6/2026
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page.
ModificadaAlta (7.5)2.4%—Cgiscript.net Cspassword4/10/200216/6/2026
CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users.
ModificadaMedia (5)3.7%—Nrl.navy One-time Passwords IN Everything31/12/200116/6/2026
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.
ModificadaMedia (4.6)0.35%—Counterpane Password Safe13/9/200116/6/2026
Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory…
ModificadaAlta (10)1.6%—Quakenbush NT Password AppraiserAI1/1/199916/6/2026
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
Orbitaley — Vulnerabilidades