Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.1% | — | Symantec Norton Password Manager | 29/8/2018 | 17/6/2026 | The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials. | |
| Modificada | Alta (7.8) | 2.6% | — | Kaspersky Password Manager | 19/4/2018 | 17/6/2026 | Unauthorized code execution from specific DLL and is known as DLL Hijacking attack in Kaspersky Password Manager versions before 8.0.6.538. | |
| Modificada | Media (6.1) | 1.5% | — | Zohocorp Manageengine Password Manager PRO | 15/12/2017 | 17/6/2026 | Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. | |
| Modificada | Alta (7.5) | 1.4% | — | KED Password Manager Project KED Password Manager | 27/4/2017 | 17/6/2026 | kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and… | |
| Modificada | Alta (8) | 1.2% | — | Zohocorp Password Manager PRO | 20/4/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500). | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Trendmicro Password Manager | 12/4/2016 | 17/6/2026 | The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. | |
| Modificada | Media (6.5) | 3.5% | — | Zohocorp Manageengine Password Manager PRO | 8/7/2015 | 17/6/2026 | SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary SQL commands via the ANDOR parameter, as demonstrated by a request to… | |
| Modificada | Media (6.4) | 2.4% | — | Manageengine Password Manager PRO | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Zohocorp Manageengine Password Manager PROZohocorp Manageengine It360 | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products,… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Manageengine It360Manageengine Password Manager PROManageengine Desktop Central | 5/12/2014 | 17/6/2026 | SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed… | |
| Modificada | Media (6.5) | 36% | 💥 Exploit | Manageengine Password Manager PRO | 17/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2)… | |
| Modificada | Media (6.5) | 13% | 💥 Exploit | Zohocorp Manageengine Password Manager PRO | 17/11/2014 | 17/6/2026 | SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Dell Quest ONE Password Manager | 24/10/2013 | 17/6/2026 | The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters. | |
| Modificada | Baja (2.1) | 0.30% | — | Martinicreations Passmanlite Password Manager | 13/5/2011 | 16/6/2026 | The MartiniCreations PassmanLite Password Manager application before 1.48 for Android stores the master password and unspecified other account information in cleartext, which allows local users to obtain sensitive information by leveraging shell access. | |
| Modificada | Media (4.3) | 1.3% | — | Manageengine Password Manager PROManageengine Password Manager Pro6.1 | 22/12/2009 | 16/6/2026 | The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified… | |
| Modificada | Media (6.4) | 1.3% | — | IBM Client Security Password Manager | 5/10/2006 | 16/6/2026 | IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. |