Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Honeywell Alerton Compass | 15/7/2022 | 17/6/2026 | Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other… | |
| Modificada | Media (4.8) | 1.1% | — | Passport Project Passport | 1/7/2022 | 17/6/2026 | This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of being closed. | |
| Modificada | Media (4.8) | 0.52% | — | 1password1password IN THE Browser1password Command-line1password Command Line Interface+2 | 15/6/2022 | 17/6/2026 | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service. | |
| Modificada | Crítica (9.1) | 0.95% | — | Palantir Foundry Multipass | 14/6/2022 | 17/6/2026 | The Multipass service was found to have code paths that could be abused to cause a denial of service for authentication or authorization operations. A malicious attacker could perform an application-level denial of service attack, potentially causing authentication and/or authorization operations to fail for the… | |
| Modificada | Media (4.6) | 0.25% | — | Samsung Pass | 7/6/2022 | 17/6/2026 | Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (7.8) | 0.27% | — | Trendmicro Password Manager | 27/5/2022 | 17/6/2026 | EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the… | |
| Modificada | Media (5.4) | 0.50% | — | Covid 19 Travel Pass Management System Project Covid 19 Travel Pass Management System | 24/5/2022 | 17/6/2026 | Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname. | |
| Modificada | Crítica (9.8) | 1.1% | — | Covid 19 Travel Pass Management System Project Covid 19 Travel Pass Management System | 24/5/2022 | 17/6/2026 | Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status | |
| Modificada | Alta (7.5) | 1.9% | — | Random Password Generator Project Random Password Generator | 18/5/2022 | 17/6/2026 | The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction. | |
| Modificada | Crítica (9.8) | 1.2% | — | Covid 19 Travel Pass Management Project Covid 19 Travel Pass Management | 17/5/2022 | 17/6/2026 | In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks. | |
| Modificada | Media (5.4) | 0.58% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (4.8) | 0.57% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.2) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Alta (8.8) | 1.1% | — | Arubanetworks Clearpass Policy Manager | 17/5/2022 | 17/6/2026 | A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (6.5) | 1.1% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Media (4.9) | 0.98% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manage that address this security vulnerability. | |
| Modificada | Alta (7.2) | 1.5% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | |
| Modificada | Crítica (9.1) | 2.2% | — | Arubanetworks Clearpass Policy Manager | 16/5/2022 | 17/6/2026 | A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. |