Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.38%—Teampass4/6/202317/6/2026
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaCrítica (9)0.91%—Teampass3/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaAlta (8.1)0.84%—Teampass3/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaAlta (8.7)0.74%—Teampass3/6/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaMedia (5.4)0.68%💥 PoCTeampass31/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaAlta (8.8)1.6%💥 PoCTeampass24/5/202317/6/2026
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
ModificadaCrítica (9.8)0.75%—Oretnom23 Employee AND Visitor Gate Pass Logging System23/5/202317/6/2026
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
ModificadaAlta (7.5)4.4%💥 PoCKeepass15/5/202317/6/2026
In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be a KeePass process dump, swap file (pagefile.sys), hibernation file (hiberfil.sys), or RAM dump of the entire system. The first character…
ModificadaAlta (7.8)0.47%—Soft-o Free Password Manager12/5/202317/6/2026
A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution.
ModificadaMedia (5.4)0.61%💥 PoCTeampass9/5/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
ModificadaMedia (5.4)0.61%💥 PoCTeampass5/5/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
ModificadaMedia (4.9)0.90%—Changingtec Mobile ONE Time Password27/4/202317/6/2026
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaCrítica (9.8)1.9%—Broccoli-compass Project Broccoli-compass24/4/202317/6/2026
broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
ModificadaMedia (6.5)0.38%—Fastify Passport21/4/202317/6/2026
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. The CSRF (Cross-Site Request Forger) protection enforced by the `@fastify/csrf-protection` library, when combined with `@fastify/passport` in affected versions, can be bypassed by network and same-site attackers.…
ModificadaAlta (8.1)0.75%—Fastify Passport21/4/202317/6/2026
@fastify/passport is a port of passport authentication library for the Fastify ecosystem. Applications using `@fastify/passport` in affected versions for user authentication, in combination with `@fastify/session` as the underlying session management mechanism, are vulnerable to session fixation attacks from network…
ModificadaAlta (8.8)0.73%—Oretnom23 Employee AND Visitor Gate Pass Logging System15/4/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /admin/maintenance/view_designation.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is…
ModificadaMedia (5.4)0.36%—Teampass13/4/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
ModificadaMedia (5.3)0.46%—Mendix Forgot Password11/4/202317/6/2026
A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the module contain an observable response…
ModificadaAlta (8.8)0.35%—Hcltech HCL Compass2/4/202317/6/2026
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
ModificadaMedia (4.9)0.33%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by…
ModificadaMedia (5.5)0.16%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability exists in the ClearPass OnGuard Ubuntu agent that allows for an attacker with local Ubuntu instance access to potentially obtain sensitive information. Successful Exploitation of this vulnerability allows an attacker to retrieve information that is of a sensitive nature to the ClearPass/OnGuard…
ModificadaAlta (8.8)0.46%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an attacker with read-only privileges to perform actions that change the state of the ClearPass Policy Manager instance. Successful exploitation of this vulnerability allows an attacker to complete state-changing actions in the…
ModificadaMedia (6.1)0.47%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of…
ModificadaMedia (6.1)0.47%—Arubanetworks Clearpass Policy Manager22/3/202317/6/2026
Vulnerabilities within the web-based management interface of ClearPass Policy Manager could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of…
Orbitaley — Vulnerabilidades