Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.38% | — | Teampass | 4/6/2023 | 17/6/2026 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Crítica (9) | 0.91% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.1) | 0.84% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.7) | 0.74% | — | Teampass | 3/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Media (5.4) | 0.68% | 💥 PoC | Teampass | 31/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Alta (8.8) | 1.6% | 💥 PoC | Teampass | 24/5/2023 | 17/6/2026 | Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | |
| Modificada | Crítica (9.8) | 0.75% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 23/5/2023 | 17/6/2026 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php. | |
| Modificada | Alta (7.5) | 4.4% | 💥 PoC | Keepass | 15/5/2023 | 17/6/2026 | In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character… | |
| Modificada | Alta (7.8) | 0.47% | — | Soft-o Free Password Manager | 12/5/2023 | 17/6/2026 | A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution. | |
| Modificada | Media (5.4) | 0.61% | 💥 PoC | Teampass | 9/5/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | |
| Modificada | Media (5.4) | 0.61% | 💥 PoC | Teampass | 5/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | |
| Modificada | Media (4.9) | 0.90% | — | Changingtec Mobile ONE Time Password | 27/4/2023 | 17/6/2026 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files. | |
| Modificada | Alta (7.8) | 0.81% | — | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 26/4/2023 | 17/6/2026 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to… | |
| Modificada | Crítica (9.8) | 1.9% | — | Broccoli-compass Project Broccoli-compass | 24/4/2023 | 17/6/2026 | broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. | |
| Modificada | Media (6.5) | 0.38% | — | Fastify Passport | 21/4/2023 | 17/6/2026 | @fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affected versions, can be bypassed by network and same-site attackers.… | |
| Modificada | Alta (8.1) | 0.75% | — | Fastify Passport | 21/4/2023 | 17/6/2026 | @fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in combination with `@fastify/session` as the underlying session management mechanism, are vulnerable to session fixation attacks from network… | |
| Modificada | Alta (8.8) | 0.73% | — | Oretnom23 Employee AND Visitor Gate Pass Logging System | 15/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /admin/maintenance/view_designation.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is… | |
| Modificada | Media (5.4) | 0.36% | — | Teampass | 13/4/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. | |
| Modificada | Media (5.3) | 0.46% | — | Mendix Forgot Password | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the module contain an observable response… | |
| Modificada | Alta (8.8) | 0.35% | — | Hcltech HCL Compass | 2/4/2023 | 17/6/2026 | HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request. | |
| Modificada | Media (4.9) | 0.33% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by… | |
| Modificada | Media (5.5) | 0.16% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard… | |
| Modificada | Alta (8.8) | 0.46% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker to complete state-changing actions in the… | |
| Modificada | Media (6.1) | 0.47% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of… | |
| Modificada | Media (6.1) | 0.47% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of… |