Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.57%—Rajkakadiya Password Protected Store FOR Woocommerce5/3/202417/6/2026
The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and content.
ModificadaMedia (4.8)0.34%—Wpexperts Password Protected29/2/202417/6/2026
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possible…
ModificadaMedia (5.3)0.48%—Passwordprotectwp Password Protect Wordpress29/2/202417/6/2026
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.
ModificadaMedia (5.3)0.48%—Wpchill Passster29/2/202417/6/2026
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.6.2 via API. This makes it possible for unauthenticated attackers to obtain post titles, slugs, IDs, content and other metadata including passwords of…
AnalizadaMedia (4.8)0.35%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services…
AnalizadaMedia (6.5)0.52%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services…
AnalizadaMedia (4.8)0.36%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the…
AnalizadaMedia (4.8)0.36%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's…
AnalizadaAlta (8.8)0.92%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
AnalizadaAlta (8.8)0.92%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
AnalizadaAlta (8.8)0.92%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
AnalizadaAlta (8.8)0.93%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
AnalizadaAlta (8.8)0.93%—Arubanetworks Clearpass Policy Manager27/2/202417/6/2026
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
ModificadaAlta (7.5)0.50%—N-able Passportal8/2/202417/6/2026
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
ModificadaAlta (7.5)0.98%—Netvision Airpass15/1/202417/6/2026
NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
ModificadaMedia (6.1)0.45%—Spassarop Owasp Antisamy .net2/1/202417/6/2026
OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0, there is a potential for a mutation cross-site scripting (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the…
ModificadaAlta (8.1)0.63%—Passwork26/12/202317/6/2026
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.
ModificadaAlta (8.8)0.52%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click…
ModificadaCrítica (9.8)1.0%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA…
ModificadaCrítica (9.8)1.2%—Ltb-project Self Service Password21/12/202317/6/2026
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.
ModificadaCrítica (9.8)1.3%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
ModificadaCrítica (9.8)1.0%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire…
ModificadaCrítica (9.8)1.1%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
ModificadaCrítica (9.8)1.1%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device
ModificadaCrítica (9.8)1.1%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device.
Orbitaley — Vulnerabilidades