Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)1.1%—Symantec Norton Password Manager29/8/201817/6/2026
The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials.
ModificadaAlta (7.8)2.6%—Kaspersky Password Manager19/4/201817/6/2026
Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538.
ModificadaMedia (6.1)1.5%—Zohocorp Manageengine Password Manager PRO15/12/201717/6/2026
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
ModificadaAlta (7.5)1.4%—KED Password Manager Project KED Password Manager27/4/201717/6/2026
kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and…
ModificadaAlta (8)1.2%—Zohocorp Password Manager PRO20/4/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
ModificadaCrítica (9.8)22%💥 ExploitTrendmicro Password Manager12/4/201617/6/2026
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
ModificadaMedia (6.5)3.5%—Zohocorp Manageengine Password Manager PRO8/7/201517/6/2026
SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to…
ModificadaMedia (6.4)2.4%—Manageengine Password Manager PRO16/12/201417/6/2026
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
ModificadaAlta (7.5)13%💥 ExploitZohocorp Manageengine Password Manager PROZohocorp Manageengine It3605/12/201417/6/2026
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products,…
ModificadaAlta (7.5)38%💥 ExploitManageengine It360Manageengine Password Manager PROManageengine Desktop Central5/12/201417/6/2026
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed…
ModificadaMedia (6.5)36%💥 ExploitManageengine Password Manager PRO17/11/201417/6/2026
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2)…
ModificadaMedia (6.5)13%💥 ExploitZohocorp Manageengine Password Manager PRO17/11/201417/6/2026
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.
ModificadaMedia (5)5.9%💥 ExploitDell Quest ONE Password Manager24/10/201317/6/2026
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.
ModificadaBaja (2.1)0.30%—Martinicreations Passmanlite Password Manager13/5/201116/6/2026
The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access.
ModificadaMedia (4.3)1.3%—Manageengine Password Manager PROManageengine Password Manager Pro6.122/12/200916/6/2026
The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified…
ModificadaMedia (6.4)1.3%—IBM Client Security Password Manager5/10/200616/6/2026
IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page.
ModificadaBaja (2.1)0.37%—Citrix Metaframe Password Manager2/5/200516/6/2026
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
Orbitaley — Vulnerabilidades