Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.37%—AS Password Field IN Default Registration FormAI6/1/202630/9/2026
The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for…
AplazadaAlta (8.6)0.41%—Ltb-project Self Service PasswordAI19/12/202517/6/2026
LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting…
AplazadaMedia (5.4)0.23%—Application PasswordsAI6/12/202517/6/2026
The Application Passwords plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'reject_url' parameter in all versions up to, and including, 0.1.3. This is due to insufficient input sanitization and output escaping on user supplied URLs, which allows javascript: URI schemes to be embedded in the…
AplazadaBaja (3.7)0.31%—Wpexperts Password ProtectedAI25/10/202517/6/2026
The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the…
AplazadaMedia (4.3)0.20%—Miniorange Password Policy ManagerAI25/10/202530/9/2026
The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'moppm_ajax' AJAX endpoint in all versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (7.1)0.30%—Calvaweb Password Only LoginAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password only login password-only-login allows Reflected XSS.This issue affects Password only login: from n/a through <= 0.2.
AplazadaCrítica (9.8)0.79%—Ownid Passwordless LoginAI15/10/202517/6/2026
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to…
AplazadaMedia (4.3)0.17%—Andy Moyle Emergency Password ResetAI22/9/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3.
AplazadaCrítica (9.8)0.24%—Bedevious Password Reset With Code FOR Wordpress Rest APIAI18/9/202517/6/2026
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
AplazadaBaja (3.2)0.15%—Clickstudios PasswordstateAI16/9/202530/9/2026
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.
AplazadaMedia (6.1)0.22%—WP Edit Password ProtectedAI11/9/202517/6/2026
The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
AplazadaAlta (7.3)0.34%—Opentext Self Service Password ResetAI29/8/202517/6/2026
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3.
AnalizadaMedia (6.5)0.32%—Passwordprotectwp Password Protect Wordpress14/8/202517/6/2026
The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API.
AplazadaMedia (6.9)0.37%—Thinbus Javascript Secure Remote PasswordAI7/8/202517/6/2026
Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted to 2048 bits). The…
AplazadaCrítica (9.4)1.5%—GlosswordAI5/8/202516/6/2026
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the gw_temp/a/ directory. Due to insufficient validation of file…
AplazadaAlta (7.6)0.20%—Oneidentity Password ManagerAI14/7/202517/6/2026
The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged…
AnalizadaAlta (7.8)0.17%—Trendmicro Password Manager10/7/202517/6/2026
Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation.
AnalizadaMedia (6.6)0.22%—Trendmicro Password Manager17/6/202517/6/2026
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password…
AplazadaAlta (8.8)0.58%—Miniorange Password Policy ManagerAI9/6/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects Password Policy Manager: from n/a through <= 2.0.4.
AplazadaMedia (6.5)0.25%—Wordwebsoftware Crossword Compiler PuzzlesAI23/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Stored XSS.This issue affects Crossword Compiler Puzzles: from n/a through <= 14.5.
AplazadaCrítica (9.9)0.50%—Wordwebsoftware Crossword Compiler PuzzlesAI23/5/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-compiler-puzzles allows Upload a Web Shell to a Web Server.This issue affects Crossword Compiler Puzzles: from n/a through <= 5.2.
AplazadaMedia (5.7)0.16%—Hypr PasswordlessAI21/5/202517/6/2026
Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.
AnalizadaMedia (4.8)0.25%—ONE Time Password Project ONE Time Password21/5/202517/6/2026
Authentication Bypass by Capture-replay vulnerability in Drupal One Time Password allows Remote Services with Stolen Credentials.This issue affects One Time Password: from 0.0.0 before 1.3.0.
AnalizadaMedia (4.8)0.31%—ONE Time Password Project ONE Time Password21/5/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.
AnalizadaMedia (4.8)0.25%—ONE Time Password Project ONE Time Password21/5/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal One Time Password allows Functionality Bypass.This issue affects One Time Password: from 0.0.0 before 1.3.0.