Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.67% | — | Password Recovery Project Password Recovery | 4/9/2023 | 17/6/2026 | Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has… | |
| Modificada | Media (5.3) | 0.61% | — | Password Recovery Project Password Recovery | 4/9/2023 | 17/6/2026 | User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database. | |
| Modificada | Alta (8.1) | 0.68% | — | Digi RealportDigi Connectport TS 8/16 FirmwareDigi Passport FirmwareDigi Connectport LTS 8/16/32 Firmware+16 | 31/8/2023 | 17/6/2026 | Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment. | |
| Modificada | Media (6.1) | 3.1% | — | Zohocorp Manageengine Password Manager PRO | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload. | |
| Modificada | Crítica (9.8) | 0.92% | — | University Compass Project University Compass | 28/7/2023 | 17/6/2026 | university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument. | |
| Modificada | Alta (7.2) | 1.1% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file. | |
| Modificada | Media (4.8) | 0.59% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php. | |
| Modificada | Media (4.8) | 0.58% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file. | |
| Modificada | Alta (7.2) | 1.3% | — | Phpgurukul Rail Pass Management System | 28/7/2023 | 17/6/2026 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file. | |
| Modificada | Alta (7.5) | 0.88% | — | Siemens Sipass Integrated | 11/7/2023 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V2.90.3.8). Affected server applications improperly check the size of data packets received for the configuration client login, causing a stack-based buffer overflow. This could allow an unauthenticated remote attacker to crash the server… | |
| Modificada | Media (5.4) | 0.63% | — | Teampass | 10/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Alta (7.5) | 0.83% | — | Teampass | 8/7/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 8/7/2023 | 17/6/2026 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Alta (7.2) | 1.1% | — | Teampass | 8/7/2023 | 17/6/2026 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 6/7/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | |
| Modificada | Media (4.6) | 0.25% | — | Samsung Pass | 6/7/2023 | 17/6/2026 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device. | |
| Modificada | Media (4.6) | 0.25% | — | Samsung Pass | 6/7/2023 | 17/6/2026 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass. | |
| Modificada | Media (5.5) | 0.16% | — | Samsung Pass | 6/7/2023 | 17/6/2026 | Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed. | |
| Modificada | Media (4.8) | 0.40% | — | Wpexperts Password Protected | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions. | |
| Modificada | Media (5.5) | 0.24% | — | Keepassxc | 19/6/2023 | 17/6/2026 | In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to… | |
| Modificada | Crítica (9.8) | 0.55% | — | Phpgurukul Rail Pass Management System | 15/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be… | |
| Modificada | Media (5.4) | 0.54% | — | Teampass | 10/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (4.6) | 0.52% | — | Teampass | 10/6/2023 | 17/6/2026 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9. |