Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 1.1% | 💥 Exploit | PasswordpusherAI | 22/8/2026 | 23/9/2026 | PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Smilepass Selfie LoginAI | 22/8/2026 | 26/8/2026 | The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators. | |
| Aplazada | Media (5.3) | 0.35% | — | PasssterAI | 21/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password protection, comparing them as an unanchored substring of the request URI rather than against the resolved route, allowing an unauthenticated attacker to… | |
| Pendiente de análisis | Media (6.9) | 0.14% | — | ARM HDD PasswordAI | 19/8/2026 | 31/8/2026 | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | |
| Aplazada | Media (5.2) | 0.18% | — | HashcatAIKeepassAI | 17/8/2026 | 24/9/2026 | hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allows attackers to corrupt adjacent heap memory by supplying an oversized ninth hash field token. The module accepts up to 600 hex characters for the ninth token field but… | |
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation. | |
| Pendiente de análisis | Alta (8.8) | 3.1% | — | Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI | 13/8/2026 | 31/8/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection. | |
| Aplazada | Alta (8.1) | 0.75% | — | Ventraconnect Social Login Passwordless LoginAI | 12/8/2026 | 12/8/2026 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me… | |
| Pendiente de análisis | Media (5.1) | 0.13% | — | Samsung Pass AutofillAI | 10/8/2026 | 18/8/2026 | Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |
| Aplazada | Alta (7.5) | 0.44% | — | Wpexperts Password ProtectedAI | 7/8/2026 | 26/8/2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content… | |
| Aplazada | Alta (8.6) | 0.44% | — | SyspassAI | 6/8/2026 | 24/9/2026 | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-concatenating the backup directory path $this->path directly into the command line ('tar czf ' . $backupFileApp . ' ' . BASE_PATH . ' --exclude \"' . $this->path . '\"… | |
| Aplazada | Baja (2.7) | 0.30% | — | PasssterAI | 6/8/2026 | 29/9/2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read the content of protected pages and posts… | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allowing unauthenticated users to recover the protected content without knowing the password. | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticated users to read the full content, title, and excerpt of category-locked posts through the core REST API. | |
| Aplazada | Alta (7.5) | 0.43% | — | PasssterAI | 5/8/2026 | 26/8/2026 | The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint, allowing unauthenticated users to disclose the content of non-public (draft, private, and pending) posts on sites that have a captcha provider configured. | |
| Analizada | Alta (7.4) | 0.13% | — | Devolutions Password Manager | 29/7/2026 | 21/8/2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | |
| Aplazada | Alta (8.8) | 0.51% | — | WP Password PolicyAI | 28/7/2026 | 29/7/2026 | The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the… | |
| Aplazada | Alta (8.6) | 2.0% | — | SyspassAI | 24/7/2026 | 27/7/2026 | sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands as the web server process user by setting a malicious backup path and triggering a backup. The FileBackupService builds a tar shell command via string concatenation,… | |
| Aplazada | Alta (7.1) | 0.30% | — | SyspassAI | 24/7/2026 | 27/7/2026 | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag to trigger unauthorized decryption and persistent storage of any vault account's password by exploiting the absence of AccountAcl checks in the public link creation… | |
| Aplazada | Alta (8.7) | 0.39% | — | SyspassAI | 24/7/2026 | 27/7/2026 | sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods… | |
| Aplazada | Alta (8.6) | 0.39% | — | SyspassAI | 24/7/2026 | 27/7/2026 | sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply… | |
| Analizada | Alta (8.4) | 0.21% | — | Mongodb Compass | 22/7/2026 | 30/9/2026 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom browser open command for OIDC auth flow that is usually can be set only globally via Compass settings. | |
| Aplazada | Alta (7.5) | 0.49% | — | Crypt PasswordAI | 20/7/2026 | 20/7/2026 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Crypt-passwordAI | 20/7/2026 | 20/7/2026 | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography. |