Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.12%—Hypr PasswordlessAI21/5/202517/6/2026
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1.
AplazadaMedia (4.2)0.22%—Buddypress Force Password ChangeAI24/4/202517/6/2026
The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for…
AplazadaMedia (5.3)0.36%—Wpexperts Password ProtectedAI17/4/202517/6/2026
The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This…
AnalizadaCrítica (9.8)1.1%—Netwrix Password Secure3/4/202517/6/2026
Netwrix Password Secure through 9.2 allows command injection.
ModificadaCrítica (9.8)1.6%—Netwrix Password Secure3/4/202517/6/2026
Netwrix Password Secure 9.2.0.32454 allows OS command injection.
AnalizadaMedia (4.6)0.31%—Teampasswordmanager Team Password Manager4/3/202517/6/2026
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.
AplazadaMedia (4.3)0.16%—Will Anderson Minimum-password-strengthAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength allows Cross Site Request Forgery.This issue affects Minimum Password Strength: from n/a through <= 1.2.0.
AplazadaMedia (5.2)0.26%—Roboform Password ManagerAI17/2/202517/6/2026
Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information.
AplazadaAlta (7.1)0.23%—WP Busters Passwordless WPAI27/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint passwordless-wp allows Reflected XSS.This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through <= 1.1.6.
AplazadaAlta (7.1)0.20%—Marcucci Password Protect PluginAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored XSS.This issue affects Password Protect Plugin for WordPress: from n/a through <= 0.8.1.0.
AnalizadaMedia (6.5)0.49%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaMedia (4.3)0.39%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaAlta (7.5)0.51%—Hirewebxperts Passwords Manager16/1/202517/6/2026
The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaMedia (4.8)0.27%—View Password Project View Password9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4.
AplazadaAlta (7.1)0.39%—Frankkoenen Ldap Login Password AND Role ManagerAI7/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= 1.0.12.
AplazadaMedia (5.7)0.21%—Apnotic Password PusherAI30/12/202417/6/2026
Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user logs out, potentially allowing session hijacking. Although the session token is replaced and…
AplazadaMedia (6.1)0.22%—Password FOR WPAI12/12/202417/6/2026
The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web…
AplazadaAlta (8.8)0.41%—Clickstudios PasswordstateAI29/11/202417/6/2026
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.
AplazadaMedia (5.3)0.54%—Apnotic Password PusherAI20/11/202417/6/2026
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of…
AplazadaCrítica (9.6)0.80%💥 PoCGunghoinc Exclusive Content Password ProtectAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0.
AplazadaAlta (7.1)0.27%—Techdabang User Password ResetAI9/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techdabang User Password Reset user-password-reset allows Reflected XSS.This issue affects User Password Reset: from n/a through <= 1.0.
AplazadaAlta (7.1)0.34%—Apnotic Password PusherAI7/11/202417/6/2026
Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting versions `v1.41.1` through and including `v.1.48.0`. The issue arises from an un-sanitized parameter which could allow…
AplazadaBaja (2)0.14%—Enpass Password ManagerAI26/9/202417/6/2026
A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is…
AplazadaCrítica (9.8)51%💥 ExploitOneidentity Safeguard FOR Privileged PasswordsAI30/8/202417/6/2026
One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.
AnalizadaAlta (8.8)3.0%—Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO28/8/202417/6/2026
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
Orbitaley — Vulnerabilidades