Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |
| Modificada | Media (4.3) | 1.3% | — | WEB Animations Password Protect | 31/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | WEB Animations Password Protect | 30/8/2004 | 16/6/2026 | SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp. | |
| Modificada | Media (5) | 1.3% | — | Coffeecup Software Coffeecup Password Wizard | 31/12/2003 | 16/6/2026 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error. | |
| Modificada | Media (5.1) | 1.3% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. | |
| Modificada | Alta (7.5) | 2.4% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users. | |
| Modificada | Media (5) | 3.7% | — | Nrl.navy One-time Passwords IN Everything | 31/12/2001 | 16/6/2026 | One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist. | |
| Modificada | Media (4.6) | 0.35% | — | Counterpane Password Safe | 13/9/2001 | 16/6/2026 | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory… | |
| Modificada | Alta (10) | 1.6% | — | Quakenbush NT Password AppraiserAI | 1/1/1999 | 16/6/2026 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. |