Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.61% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further privileges on the ClearPass… | |
| Modificada | Alta (7.8) | 0.18% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges to those of a higher role. A successful exploit allows malicious users to execute arbitrary code with root level privileges on the Linux instance. | |
| Modificada | Crítica (9.8) | 0.96% | — | Arubanetworks Clearpass Policy Manager | 22/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise. | |
| Modificada | Alta (7.5) | 8.4% | 💥 Exploit | Teampass | 21/3/2023 | 17/6/2026 | SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | |
| Modificada | Media (4.8) | 0.39% | — | WP Htpasswd Project WP Htpasswd | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matteo Candura WP htpasswd plugin <= 1.7 versions. | |
| Modificada | Media (5.4) | 0.52% | — | Teampass | 17/3/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | |
| Modificada | Media (5.4) | 0.52% | — | Syspass | 6/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 3.2.5 is able to address this issue. The… | |
| Modificada | Alta (7.1) | 0.82% | — | Teampass | 27/2/2023 | 17/6/2026 | External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22. | |
| Modificada | Alta (7.8) | 0.23% | — | Siemens Sipass Integrated Acc-ap FirmwareSiemens Sipass Integrated Ac5102 (acc-g2) Firmware | 14/2/2023 | 17/6/2026 | A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V2.85.44), SiPass integrated ACC-AP (All versions < V2.85.43). Affected devices improperly sanitize user input on the telnet command line interface. This could allow an authenticated user to escalate privileges by injecting… | |
| Modificada | Media (5.4) | 0.65% | — | Passwordprotectwp Password Protect Wordpress | 6/2/2023 | 17/6/2026 | The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Alta (7.5) | 0.82% | — | Passster Project Passter | 23/1/2023 | 17/6/2026 | The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request. | |
| Modificada | Media (5.4) | 0.39% | — | Passster Project Passter | 23/1/2023 | 17/6/2026 | The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Media (5.5) | 3.7% | 💥 PoC | Keepass | 22/1/2023 | 17/6/2026 | KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that level of access… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Media (5.3) | 0.72% | — | Surpass Project Surpass | 8/1/2023 | 17/6/2026 | A vulnerability has been found in SUKOHI Surpass and classified as critical. This vulnerability affects unknown code of the file src/Sukohi/Surpass/Surpass.php. The manipulation of the argument dir leads to pathname traversal. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as… | |
| Modificada | Crítica (9.8) | 71% | — | Zohocorp Manageengine Password Manager PROZohocorp Manageengine Pam360Zohocorp Manageengine Access Manager Plus | 5/1/2023 | 17/6/2026 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. | |
| Modificada | Media (5.5) | 0.18% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability exists in the ClearPass OnGuard macOS agent that allows for an attacker with local macOS instance access to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that is of a sensitive nature in Aruba ClearPass Policy Manager version(s):… | |
| Modificada | Media (4.5) | 0.27% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability exists in the ClearPass Policy Manager cluster communications that allow for an attacker in a privileged network position to potentially obtain sensitive information. A successful exploit could allow an attacker to retrieve information that allows for unauthorized actions as a privileged user on the… | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in… | |
| Modificada | Alta (7.2) | 1.4% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in… | |
| Modificada | Alta (8.8) | 1.4% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in… | |
| Modificada | Alta (7.8) | 0.18% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability in the ClearPass OnGuard Windows agent could allow malicious users on a Windows instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with NT AUTHORITY\SYSTEM level privileges on the Windows instance in Aruba ClearPass Policy Manager… | |
| Modificada | Alta (7.8) | 0.22% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the Linux instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy… | |
| Modificada | Alta (7.8) | 0.22% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges. A successful exploit could allow these users to execute arbitrary code with root level privileges on the macOS instance in Aruba ClearPass Policy Manager version(s): ClearPass Policy… | |
| Modificada | Media (4.8) | 0.42% | — | Arubanetworks Clearpass Policy Manager | 5/1/2023 | 17/6/2026 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's… |