Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 0.40% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Analizada | Crítica (9.9) | 0.37% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/9/2026 | 28/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses… | |
| Aplazada | Media (5.5) | 0.32% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC… | |
| Aplazada | Alta (7.2) | 0.46% | — | Storeapps Temporary Login Without PasswordAI | 12/9/2026 | 14/9/2026 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing… | |
| Aplazada | Media (5.3) | 0.31% | — | PasssterAI | 11/9/2026 | 11/9/2026 | Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | |
| Aplazada | Crítica (9.1) | 0.31% | — | Passport Saml EncryptedAI | 10/9/2026 | 10/9/2026 | passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned assertion that gets accepted as the… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Passport-saml-encryptedAI | 10/9/2026 | 11/9/2026 | passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to the assertion consumer service endpoint to… | |
| Aplazada | Alta (8) | 0.23% | — | Bulk Password ResetAI | 10/9/2026 | 10/9/2026 | The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a… | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Aruba Clearpass OnguardAI | 9/9/2026 | 10/9/2026 | A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially unauthorized operation of the vulnerable system. | |
| Aplazada | Alta (8.7) | 0.37% | — | PasswordpusherAI | 9/9/2026 | 10/9/2026 | PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is… | |
| Aplazada | Media (4.6) | 0.17% | — | KeepassAI | 9/9/2026 | 10/9/2026 | KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocation of gigabytes of memory, causing the application to consume resources and… | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path… | |
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,… | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 14/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the… | |
| Aplazada | Media (5.3) | 0.21% | — | WP Edit Password ProtectedAI | 2/9/2026 | 3/9/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. | |
| Aplazada | Media (5.3) | 0.21% | — | PasssterAI | 2/9/2026 | 3/9/2026 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs | |
| Aplazada | Media (5.3) | 0.19% | — | PasssterAI | 2/9/2026 | 3/9/2026 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI | 2/9/2026 | 8/9/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | |
| Aplazada | Crítica (9.3) | 0.63% | — | Teampasswordmanager Team Password ManagerAI | 1/9/2026 | 23/9/2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | |
| Pendiente de análisis | Crítica (9.3) | 0.25% | — | 3DS 3dpassportAI3dswymerAI | 27/8/2026 | 8/9/2026 | An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts. |