Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.9% | — | Webfactoryltd WP Reset PRO | 18/11/2021 | 17/6/2026 | Authenticated Database Reset vulnerability in WordPress WP Reset PRO Premium plugin (versions <= 5.98) allows any authenticated user to wipe the entire database regardless of their authorization. It leads to a complete website reset and takeover. | |
| Modificada | Alta (8.8) | 0.71% | — | Webfactoryltd WP Reset PRO | 18/11/2021 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WebFactory Ltd. WP Reset PRO plugin <= 5.98 versions. | |
| Modificada | Media (5.4) | 0.63% | — | Webfactoryltd WP Reset | 12/7/2021 | 17/6/2026 | The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Alta (7.5) | 1.0% | — | Thycotic Password Reset Server | 11/6/2021 | 17/6/2026 | Thycotic Password Reset Server before 5.3.0 allows credential disclosure. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Self Service Password Reset | 5/11/2020 | 17/6/2026 | Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information. | |
| Modificada | Alta (8.8) | 1.9% | 💥 PoC | Anixis Password Reset Client | 30/9/2020 | 9/7/2026 | The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of… | |
| Modificada | Crítica (9.8) | 1.4% | — | Alfresco Reset Password | 18/9/2020 | 17/6/2026 | The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0 | |
| Modificada | Alta (8.8) | 1.0% | — | Alfresco Reset Password | 17/9/2020 | 17/6/2026 | The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account. | |
| Modificada | Alta (7.5) | 0.92% | — | Flexsolution Reset Password | 17/9/2020 | 17/6/2026 | The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field. | |
| Modificada | Crítica (9.1) | 23% | 💥 PoC | Webfactoryltd WP Database Reset | 16/1/2020 | 17/6/2026 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site content stored in that table), as demonstrated by a wp-admin/admin-post.php?db-reset-tables[]=comments URI. | |
| Modificada | Alta (8.8) | 2.5% | — | Webfactoryltd WP Database Reset | 16/1/2020 | 17/6/2026 | The WordPress plugin, WP Database Reset through 3.1, contains a flaw that gave any authenticated user, with minimal permissions, the ability (with a simple wp-admin/admin.php?db-reset-tables[]=users request) to escalate their privileges to administrator while dropping all other users from the table. | |
| Modificada | Media (5.9) | 0.40% | — | Microfocus Netiq Self Service Password Reset | 22/10/2019 | 17/6/2026 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The vulnerability could exploit invalid certificate validation and may result in a man-in-the-middle attack. | |
| Modificada | Alta (7) | 0.62% | 💥 PoC | Sailpoint Desktop Password Reset | 20/8/2019 | 17/6/2026 | An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to NT AUTHORITY\System. An attacker would need local access to the machine for a successful exploit. The attacker must disconnect the computer… | |
| Modificada | Crítica (9.8) | 2.1% | — | Microfocus Netiq Self Service Password Reset | 14/8/2019 | 17/6/2026 | A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4.4.0.3, 4.3.0.6, and 4.2.0.6. Upgrade to Micro Focus Self Service Password Reset (SSPR) SSPR versions 4.4.0.3, 4.3.0.6, or 4.2.0.6 as appropriate. | |
| Modificada | Alta (7.5) | 1.1% | — | Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.4. The vulnerability could be exploited to expose sensitive information. | |
| Modificada | Media (6.1) | 0.65% | — | Microfocus Netiq Self Service Password Reset | 24/6/2019 | 17/6/2026 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. The vulnerability could be exploited to enable an XSS attack. | |
| Modificada | Media (6.1) | 1.4% | — | Microfocus Self Service Password Reset | 24/3/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ Self Service Password Reset (SSPR) 2.x and 3.x before 3.3.1 HF2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Crítica (10) | 2.4% | — | Dovestones AD Self Password Reset | 24/12/2015 | 17/6/2026 | The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username. | |
| Modificada | Media (4) | 1.2% | — | HP Icewall Identity ManagerHP Icewall SSO Password Reset Option | 5/4/2014 | 17/6/2026 | Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors. | |
| Modificada | Media (6.2) | 0.77% | — | Oracle Passlogix V-go Self-service Password Reset AND OEM | 7/2/2011 | 16/6/2026 | Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is… | |
| Modificada | Alta (7.5) | 1.1% | — | Robert Heel CWT Resetbepassword | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |