Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.37% | — | AS Password Field IN Default Registration FormAI | 6/1/2026 | 30/9/2026 | The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.41% | — | Ltb-project Self Service PasswordAI | 19/12/2025 | 17/6/2026 | LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting… | |
| Aplazada | Media (5.4) | 0.23% | — | Application PasswordsAI | 6/12/2025 | 17/6/2026 | The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the… | |
| Aplazada | Baja (3.7) | 0.31% | — | Wpexperts Password ProtectedAI | 25/10/2025 | 17/6/2026 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the… | |
| Aplazada | Media (4.3) | 0.20% | — | Miniorange Password Policy ManagerAI | 25/10/2025 | 30/9/2026 | The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'moppm_ajax' AJAX endpoint in all versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (7.1) | 0.30% | — | Calvaweb Password Only LoginAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password only login password-only-login allows Reflected XSS.This issue affects Password only login: from n/a through <= 0.2. | |
| Aplazada | Crítica (9.8) | 0.79% | — | Ownid Passwordless LoginAI | 15/10/2025 | 17/6/2026 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (4.3) | 0.17% | — | Andy Moyle Emergency Password ResetAI | 22/9/2025 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3. | |
| Aplazada | Crítica (9.8) | 0.24% | — | Bedevious Password Reset With Code FOR Wordpress Rest APIAI | 18/9/2025 | 17/6/2026 | The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers. | |
| Aplazada | Baja (3.2) | 0.15% | — | Clickstudios PasswordstateAI | 16/9/2025 | 30/9/2026 | Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section. | |
| Aplazada | Media (6.1) | 0.22% | — | WP Edit Password ProtectedAI | 11/9/2025 | 17/6/2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | |
| Aplazada | Alta (7.3) | 0.34% | — | Opentext Self Service Password ResetAI | 29/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3. | |
| Analizada | Media (6.5) | 0.32% | — | Passwordprotectwp Password Protect Wordpress | 14/8/2025 | 17/6/2026 | The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API. | |
| Aplazada | Media (6.9) | 0.37% | — | Thinbus Javascript Secure Remote PasswordAI | 7/8/2025 | 17/6/2026 | Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted to 2048 bits). The… | |
| Aplazada | Crítica (9.4) | 1.5% | — | GlosswordAI | 5/8/2025 | 16/6/2026 | Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the gw_temp/a/ directory. Due to insufficient validation of file… | |
| Aplazada | Alta (7.6) | 0.20% | — | Oneidentity Password ManagerAI | 14/7/2025 | 17/6/2026 | The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged… | |
| Analizada | Alta (7.8) | 0.17% | — | Trendmicro Password Manager | 10/7/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation. | |
| Analizada | Media (6.6) | 0.22% | — | Trendmicro Password Manager | 17/6/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password… | |
| Aplazada | Alta (8.8) | 0.58% | — | Miniorange Password Policy ManagerAI | 9/6/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects Password Policy Manager: from n/a through <= 2.0.4. | |
| Aplazada | Media (6.5) | 0.25% | — | Wordwebsoftware Crossword Compiler PuzzlesAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Stored XSS.This issue affects Crossword Compiler Puzzles: from n/a through <= 14.5. | |
| Aplazada | Crítica (9.9) | 0.50% | — | Wordwebsoftware Crossword Compiler PuzzlesAI | 23/5/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload a Web Shell to a Web Server.This issue affects Crossword Compiler Puzzles: from n/a through <= 5.2. | |
| Aplazada | Media (5.7) | 0.16% | — | Hypr PasswordlessAI | 21/5/2025 | 17/6/2026 | Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1. | |
| Analizada | Media (4.8) | 0.25% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0. | |
| Analizada | Media (4.8) | 0.31% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0. | |
| Analizada | Media (4.8) | 0.25% | — | ONE Time Password Project ONE Time Password | 21/5/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0. |