Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.9%—Webfactoryltd WP Reset PRO18/11/202117/6/2026
Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover.
ModificadaAlta (8.8)0.71%—Webfactoryltd WP Reset PRO18/11/202117/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions.
ModificadaMedia (5.4)0.63%—Webfactoryltd WP Reset12/7/202117/6/2026
The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
ModificadaAlta (7.5)1.0%—Thycotic Password Reset Server11/6/202117/6/2026
Thycotic Password Reset Server before 5.3.0 allows credential disclosure.
ModificadaAlta (7.5)1.1%—Microfocus Self Service Password Reset5/11/202017/6/2026
Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.
ModificadaAlta (8.8)1.9%💥 PoCAnixis Password Reset Client30/9/20209/7/2026
The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of…
ModificadaCrítica (9.8)1.4%—Alfresco Reset Password18/9/202017/6/2026
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0
ModificadaAlta (8.8)1.0%—Alfresco Reset Password17/9/202017/6/2026
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
ModificadaAlta (7.5)0.92%—Flexsolution Reset Password17/9/202017/6/2026
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
ModificadaCrítica (9.1)23%💥 PoCWebfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI.
ModificadaAlta (8.8)2.5%—Webfactoryltd WP Database Reset16/1/202017/6/2026
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table.
ModificadaMedia (5.9)0.40%—Microfocus Netiq Self Service Password Reset22/10/201917/6/2026
Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack.
ModificadaAlta (7)0.62%💥 PoCSailpoint Desktop Password Reset20/8/201917/6/2026
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer…
ModificadaCrítica (9.8)2.1%—Microfocus Netiq Self Service Password Reset14/8/201917/6/2026
A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate.
ModificadaAlta (7.5)1.1%—Netiq Self Service Password Reset24/6/201917/6/2026
An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information.
ModificadaMedia (6.1)0.65%—Microfocus Netiq Self Service Password Reset24/6/201917/6/2026
A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack.
ModificadaMedia (6.1)1.4%—Microfocus Self Service Password Reset24/3/201617/6/2026
Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaCrítica (10)2.4%—Dovestones AD Self Password Reset24/12/201517/6/2026
The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.
ModificadaMedia (4)1.2%—HP Icewall Identity ManagerHP Icewall SSO Password Reset Option5/4/201417/6/2026
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaMedia (6.2)0.77%—Oracle Passlogix V-go Self-service Password Reset AND OEM7/2/201116/6/2026
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is…
ModificadaAlta (7.5)1.1%—Robert Heel CWT Resetbepassword15/3/201016/6/2026
SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Orbitaley — Vulnerabilidades