Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.68%—Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+415/12/202317/6/2026
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer
ModificadaMedia (4.8)0.39%—Andreasmuench Multiple Post Passwords14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andreas Münch Multiple Post Passwords allows Stored XSS.This issue affects Multiple Post Passwords: from n/a through 1.1.1.
ModificadaCrítica (9.8)1.1%—Bedevious Password Reset With Code FOR Wordpress Rest API7/12/202317/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.
ModificadaMedia (6.8)0.38%—Samsung Pass5/12/202317/6/2026
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
ModificadaMedia (6.8)0.38%—Samsung Pass5/12/202317/6/2026
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
ModificadaMedia (4.8)0.42%—Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+228/11/202317/6/2026
The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and…
ModificadaAlta (8.8)0.31%—Passionatebrains ADD Expires Headers & Optimized Minify22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions.
ModificadaAlta (8.8)0.37%—Plainviewplugins Plainview Protect Passwords18/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaMedia (6.1)0.40%—Plainviewplugins Plainview Protect Passwords14/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions.
ModificadaMedia (4.7)0.44%—Clickstudios Passwordstate13/11/202317/6/2026
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to…
ModificadaAlta (8.8)0.30%—Shawfactor Lh-password-changer9/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions.
ModificadaMedia (6.8)0.34%—Samsung Pass7/11/202317/6/2026
Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.
ModificadaBaja (3.5)0.24%—Clickstudios Passwordstate31/10/202317/6/2026
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.
ModificadaMedia (6.3)0.58%—Arubanetworks Clearpass Policy Manager25/10/202317/6/2026
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the underlying operating system leading to partial…
ModificadaMedia (5.8)0.57%—Arubanetworks Clearpass Policy Manager25/10/202317/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to send notifications to computers that are running ClearPass OnGuard. These notifications can then be used to phish users or trick them into downloading malicious software.
ModificadaMedia (6.5)0.38%—Arubanetworks Clearpass Policy Manager25/10/202317/6/2026
Vulnerabilities in the web-based management interface of ClearPass Policy Manager allow an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of these vulnerabilities allow an attacker to complete state-changing actions in the…
ModificadaAlta (8.8)0.80%—Arubanetworks Clearpass Policy Manager25/10/202317/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying…
ModificadaAlta (7.8)0.21%—Arubanetworks Clearpass Policy Manager25/10/202317/6/2026
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance.
ModificadaCrítica (9.8)0.45%—Hcltech HCL Compass19/10/202317/6/2026
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
ModificadaMedia (6.5)0.29%—Hcltech HCL Compass19/10/202317/6/2026
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
ModificadaAlta (8.8)0.48%—Hcltech HCL Compass18/10/202317/6/2026
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
ModificadaMedia (5.3)0.51%—Mendix Forgot Password10/10/202317/6/2026
A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.4.0).…
ModificadaMedia (6.1)23%—Pleasantsolutions Pleasant Password Server4/10/202317/6/2026
A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter.
ModificadaMedia (6.8)0.54%—Oneidentity Password Manager27/9/202317/6/2026
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
Orbitaley — Vulnerabilidades