Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.80%—Arubanetworks Clearpass Policy Manager5/1/202317/6/2026
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying…
ModificadaAlta (8.8)0.95%—Arubanetworks Clearpass Policy Manager5/1/202317/6/2026
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying…
ModificadaMedia (6.1)3.8%💥 ExploitAdiscon Password Manager FOR IIS26/12/202217/6/2026
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
ModificadaMedia (6.5)0.75%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit…
ModificadaMedia (6.5)0.88%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The manipulation leads to insufficiently protected credentials. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (5.3)1.3%💥 PoCClickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affects an unknown part. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (5.5)0.24%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm. Local access is required to approach this attack. The exploit…
ModificadaMedia (5.4)0.66%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected is an unknown function of the component URL Field Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
ModificadaMedia (6.5)0.88%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown processing of the file /api/browserextension/UpdatePassword/ of the component API. The manipulation of the argument PasswordID leads to…
ModificadaAlta (7.5)1.0%—Clickstudios Passwordstate19/12/202217/6/2026
A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.45%—Change Password FOR Frontend Users Project Change Password FOR Frontend Users14/12/202217/6/2026
An issue was discovered in the fe_change_pwd (aka Change password for frontend users) extension before 2.0.5, and 3.x before 3.0.3, for TYPO3. The extension fails to revoke existing sessions for the current user when the password has been changed.
ModificadaCrítica (9.8)1.2%—Passhunt Project Passhunt14/12/202217/6/2026
Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaAlta (7.5)0.77%—Auth0 Passport-wsfed-saml213/12/202217/6/2026
Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP…
ModificadaMedia (6.8)0.26%—Samsung Pass8/12/202217/6/2026
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.
ModificadaMedia (4.2)0.27%—Samsung Pass8/12/202217/6/2026
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.
ModificadaAlta (7.5)0.86%—Passeo Project Passeo6/12/202217/6/2026
Passeo is an open source python password generator. Versions prior to 1.0.5 rely on the python `random` library for random value selection. The python `random` library warns that it should not be used for security purposes due to its reliance on a non-cryptographically secure random number generator. As a result a…
ModificadaMedia (5.4)0.82%💥 PoCPassword Storage Application Project Password Storage Application21/11/202217/6/2026
Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.
ModificadaMedia (6.1)0.44%—Password Storage Application Project Password Storage Application17/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in the add-fee.php component of Password Storage Application v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cmddept parameter.
ModificadaMedia (5.5)0.18%—IBM MQ Internet Pass-thru14/11/202217/6/2026
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.
ModificadaCrítica (9.8)67%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO12/11/202217/6/2026
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.
ModificadaCrítica (9.8)75%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO12/11/202217/6/2026
Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.
ModificadaCrítica (9.8)0.43%—Samsung Pass9/11/202217/6/2026
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
ModificadaAlta (7.5)0.38%—Passwork7/11/202217/6/2026
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.
ModificadaAlta (7.5)0.38%—Passwork7/11/202217/6/2026
The PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.
ModificadaMedia (5.4)0.49%—Password Storage Application Project Password Storage Application27/10/20229/7/2026
Password Storage Application v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Setup page.