Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.12% | — | Hypr PasswordlessAI | 21/5/2025 | 17/6/2026 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in HYPR Passwordless on Windows allows Privilege Escalation.This issue affects HYPR Passwordless: before 10.1. | |
| Aplazada | Media (4.2) | 0.22% | — | Buddypress Force Password ChangeAI | 24/4/2025 | 17/6/2026 | The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plugin not properly validating a user's identity prior to updating their password through the 'bp_force_password_ajax' function in all versions up to, and including, 0.1. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.36% | — | Wpexperts Password ProtectedAI | 17/4/2025 | 17/6/2026 | The Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products – Restrict Content, Protect WooCommerce Category and more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.7 via the 'password_protected_cookie' function. This… | |
| Analizada | Crítica (9.8) | 1.1% | — | Netwrix Password Secure | 3/4/2025 | 17/6/2026 | Netwrix Password Secure through 9.2 allows command injection. | |
| Modificada | Crítica (9.8) | 1.6% | — | Netwrix Password Secure | 3/4/2025 | 17/6/2026 | Netwrix Password Secure 9.2.0.32454 allows OS command injection. | |
| Analizada | Media (4.6) | 0.31% | — | Teampasswordmanager Team Password Manager | 4/3/2025 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page. | |
| Aplazada | Media (4.3) | 0.16% | — | Will Anderson Minimum-password-strengthAI | 24/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Will Anderson Minimum Password Strength minimum-password-strength allows Cross Site Request Forgery.This issue affects Minimum Password Strength: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.2) | 0.26% | — | Roboform Password ManagerAI | 17/2/2025 | 17/6/2026 | Authentication bypass using an alternate path or channel issue exists in ”RoboForm Password Manager" App for Android versions prior to 9.7.4, which may allow an attacker with access to a device where the application is installed to bypass the lock screen and obtain sensitive information. | |
| Aplazada | Alta (7.1) | 0.23% | — | WP Busters Passwordless WPAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint passwordless-wp allows Reflected XSS.This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.20% | — | Marcucci Password Protect PluginAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored XSS.This issue affects Password Protect Plugin for WordPress: from n/a through <= 0.8.1.0. | |
| Analizada | Media (6.5) | 0.49% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX actions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (4.3) | 0.39% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pms_save_setting' and 'post_new_pass' AJAX actions in all versions up to, and including, 1.4.8. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Alta (7.5) | 0.51% | — | Hirewebxperts Passwords Manager | 16/1/2025 | 17/6/2026 | The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX fuctions in all versions up to, and including, 1.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Media (4.8) | 0.27% | — | View Password Project View Password | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4. | |
| Aplazada | Alta (7.1) | 0.39% | — | Frankkoenen Ldap Login Password AND Role ManagerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in frankkoenen ldap_login_password_and_role_manager ldap-login-password-and-role-manager allows Stored XSS.This issue affects ldap_login_password_and_role_manager: from n/a through <= 1.0.12. | |
| Aplazada | Media (5.7) | 0.21% | — | Apnotic Password PusherAI | 30/12/2024 | 17/6/2026 | Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where an attacker can copy the session cookie before a user logs out, potentially allowing session hijacking. Although the session token is replaced and… | |
| Aplazada | Media (6.1) | 0.22% | — | Password FOR WPAI | 12/12/2024 | 17/6/2026 | The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the get3_init_admin_page() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Alta (8.8) | 0.41% | — | Clickstudios PasswordstateAI | 29/11/2024 | 17/6/2026 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. | |
| Aplazada | Media (5.3) | 0.54% | — | Apnotic Password PusherAI | 20/11/2024 | 17/6/2026 | Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of… | |
| Aplazada | Crítica (9.6) | 0.80% | 💥 PoC | Gunghoinc Exclusive Content Password ProtectAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-password-protect allows Upload a Web Shell to a Web Server.This issue affects Exclusive Content Password Protect: from n/a through <= 1.1.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Techdabang User Password ResetAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techdabang User Password Reset user-password-reset allows Reflected XSS.This issue affects User Password Reset: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.34% | — | Apnotic Password PusherAI | 7/11/2024 | 17/6/2026 | Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting versions `v1.41.1` through and including `v.1.48.0`. The issue arises from an un-sanitized parameter which could allow… | |
| Aplazada | Baja (2) | 0.14% | — | Enpass Password ManagerAI | 26/9/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is… | |
| Aplazada | Crítica (9.8) | 51% | 💥 Exploit | Oneidentity Safeguard FOR Privileged PasswordsAI | 30/8/2024 | 17/6/2026 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2. | |
| Analizada | Alta (8.8) | 3.0% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 28/8/2024 | 17/6/2026 | Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option. |