Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.68% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer | |
| Modificada | Media (4.8) | 0.39% | — | Andreasmuench Multiple Post Passwords | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andreas Münch Multiple Post Passwords allows Stored XSS.This issue affects Multiple Post Passwords: from n/a through 1.1.1. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bedevious Password Reset With Code FOR Wordpress Rest API | 7/12/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15. | |
| Modificada | Media (6.8) | 0.38% | — | Samsung Pass | 5/12/2023 | 17/6/2026 | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler. | |
| Modificada | Media (6.8) | 0.38% | — | Samsung Pass | 5/12/2023 | 17/6/2026 | Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting. | |
| Modificada | Media (4.8) | 0.42% | — | Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+2 | 28/11/2023 | 17/6/2026 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and… | |
| Modificada | Alta (8.8) | 0.31% | — | Passionatebrains ADD Expires Headers & Optimized Minify | 22/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions. | |
| Modificada | Alta (8.8) | 0.37% | — | Plainviewplugins Plainview Protect Passwords | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.40% | — | Plainviewplugins Plainview Protect Passwords | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions. | |
| Modificada | Media (4.7) | 0.44% | — | Clickstudios Passwordstate | 13/11/2023 | 17/6/2026 | An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to… | |
| Modificada | Alta (8.8) | 0.30% | — | Shawfactor Lh-password-changer | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions. | |
| Modificada | Media (6.8) | 0.34% | — | Samsung Pass | 7/11/2023 | 17/6/2026 | Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication. | |
| Modificada | Baja (3.5) | 0.24% | — | Clickstudios Passwordstate | 31/10/2023 | 17/6/2026 | Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request. | |
| Modificada | Media (6.3) | 0.58% | — | Arubanetworks Clearpass Policy Manager | 25/10/2023 | 17/6/2026 | A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the underlying operating system leading to partial… | |
| Modificada | Media (5.8) | 0.57% | — | Arubanetworks Clearpass Policy Manager | 25/10/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software. | |
| Modificada | Media (6.5) | 0.38% | — | Arubanetworks Clearpass Policy Manager | 25/10/2023 | 17/6/2026 | Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker to complete state-changing actions in the… | |
| Modificada | Alta (8.8) | 0.80% | — | Arubanetworks Clearpass Policy Manager | 25/10/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying… | |
| Modificada | Alta (7.8) | 0.21% | — | Arubanetworks Clearpass Policy Manager | 25/10/2023 | 17/6/2026 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance. | |
| Modificada | Crítica (9.8) | 0.45% | — | Hcltech HCL Compass | 19/10/2023 | 17/6/2026 | HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts. | |
| Modificada | Media (6.5) | 0.29% | — | Hcltech HCL Compass | 19/10/2023 | 17/6/2026 | HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. | |
| Modificada | Alta (8.8) | 0.48% | — | Hcltech HCL Compass | 18/10/2023 | 17/6/2026 | HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser. | |
| Modificada | Media (5.3) | 0.51% | — | Mendix Forgot Password | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.4.0).… | |
| Modificada | Media (6.1) | 23% | — | Pleasantsolutions Pleasant Password Server | 4/10/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter. | |
| Modificada | Media (6.8) | 0.54% | — | Oneidentity Password Manager | 27/9/2023 | 17/6/2026 | One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges. |