Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)1.3%—Lethal Penguin PassmasterflexLethal Penguin Passmasterflexplus12/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log.
ModificadaMedia (4.9)0.33%—Counterpane Password Safe24/3/200616/6/2026
PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a…
ModificadaMedia (4.3)2.0%💥 ExploitF5 Firepass 410022/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaMedia (5)1.8%—Compex Netpassage Wpe54g2/3/200616/6/2026
uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778.
ModificadaMedia (4.6)0.80%💥 ExploitThiago Melo DE Paula Change Passwd21/1/200616/6/2026
Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.
ModificadaAlta (10)1.4%—Pear Text Password31/12/200516/6/2026
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
ModificadaMedia (4.6)0.21%—Counterpane Passwordsafe24/11/200516/6/2026
CounterPane PasswordSafe 1.x y 2.x permite a usuarios locales probar posibles claves de cifrado contra un subconjunto de los datos de claves almacenados sin realizar una función de derivación de clave (KDF) más cara, lo que reduce el tiempo de búsqueda en ataques de fuerza bruta.
ModificadaAlta (10)2.4%—Gentoo Poppassd PAM2/5/200516/6/2026
poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.
ModificadaBaja (2.1)0.37%—Citrix Metaframe Password Manager2/5/200516/6/2026
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
ModificadaMedia (4.3)1.2%—Horde Passwd2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
ModificadaAlta (7.2)0.38%—Changepassword10/1/200516/6/2026
changepassword.cgi en ChangePassword 0.8, cuando se instala con setuid, permite a usuarios locales ejecutar código de su elección modifcando la variable de entorno PATH para que apunte a un programa "make" malicioso.
ModificadaAlta (7.2)0.42%—PasswdAILinux-pamAI31/12/200416/6/2026
passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM.
ModificadaMedia (4.6)1.5%—Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+731/12/200416/6/2026
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not…
ModificadaAlta (7.2)0.65%—Passive Asset Detection System PadsAI31/12/200416/6/2026
Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability.
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
ModificadaMedia (4.3)1.3%—WEB Animations Password Protect31/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.
ModificadaAlta (7.5)1.2%💥 ExploitWEB Animations Password Protect30/8/200416/6/2026
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.
ModificadaAlta (10)4.6%💥 ExploitSquirrelmail Change Passwd PluginAI6/8/200416/6/2026
Desbordamiento de búfer en la órden chpasswd en el plugin Change_passwd anteriores a 4.0, usado en SquirrelMail, permite a usuarios locales ganar privilegios de root mediante un nombre de usuario largo.
ModificadaAlta (7.5)0.97%💥 ExploitPhppass31/12/200316/6/2026
SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters.
ModificadaMedia (5)1.3%—Coffeecup Software Coffeecup Password Wizard31/12/200316/6/2026
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
ModificadaAlta (7.2)0.30%—Bogofilter Bogopass Email Filter31/12/200216/6/2026
bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.
ModificadaMedia (4)5.8%—Phpsquidpass31/12/200216/6/2026
phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username.
ModificadaAlta (7.5)6.4%💥 ExploitChetcpasswd31/12/200216/6/2026
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field.
ModificadaMedia (6.2)0.29%—Chetcpasswd31/12/200216/6/2026
Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639.
ModificadaMedia (6.2)0.27%—Chetcpasswd31/12/200216/6/2026
Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors.
Orbitaley — Vulnerabilidades