Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.3% | — | Lethal Penguin PassmasterflexLethal Penguin Passmasterflexplus | 12/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PassMasterFlex and PassMasterFlexPlus (PassMasterFlex+) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password, or (3) User-Agent HTTP header in the Hack Log. | |
| Modificada | Media (4.9) | 0.33% | — | Counterpane Password Safe | 24/3/2006 | 16/6/2026 | PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | F5 Firepass 4100 | 22/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Media (5) | 1.8% | — | Compex Netpassage Wpe54g | 2/3/2006 | 16/6/2026 | uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778. | |
| Modificada | Media (4.6) | 0.80% | 💥 Exploit | Thiago Melo DE Paula Change Passwd | 21/1/2006 | 16/6/2026 | Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments. | |
| Modificada | Alta (10) | 1.4% | — | Pear Text Password | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. | |
| Modificada | Media (4.6) | 0.21% | — | Counterpane Passwordsafe | 24/11/2005 | 16/6/2026 | CounterPane PasswordSafe 1.x y 2.x permite a usuarios locales probar posibles claves de cifrado contra un subconjunto de los datos de claves almacenados sin realizar una función de derivación de clave (KDF) más cara, lo que reduce el tiempo de búsqueda en ataques de fuerza bruta. | |
| Modificada | Alta (10) | 2.4% | — | Gentoo Poppassd PAM | 2/5/2005 | 16/6/2026 | poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Passwd | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. | |
| Modificada | Alta (7.2) | 0.38% | — | Changepassword | 10/1/2005 | 16/6/2026 | changepassword.cgi en ChangePassword 0.8, cuando se instala con setuid, permite a usuarios locales ejecutar código de su elección modifcando la variable de entorno PATH para que apunte a un programa "make" malicioso. | |
| Modificada | Alta (7.2) | 0.42% | — | PasswdAILinux-pamAI | 31/12/2004 | 16/6/2026 | passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM. | |
| Modificada | Media (4.6) | 1.5% | — | Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+7 | 31/12/2004 | 16/6/2026 | Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not… | |
| Modificada | Alta (7.2) | 0.65% | — | Passive Asset Detection System PadsAI | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in pads.c in Passive Asset Detection System (Pads) might allow local users to execute arbitrary code via a long report file name argument. NOTE: since Pads is not normally installed setuid, this may not be a vulnerability. | |
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |
| Modificada | Media (4.3) | 1.3% | — | WEB Animations Password Protect | 31/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | WEB Animations Password Protect | 30/8/2004 | 16/6/2026 | SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp. | |
| Modificada | Alta (10) | 4.6% | 💥 Exploit | Squirrelmail Change Passwd PluginAI | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en la órden chpasswd en el plugin Change_passwd anteriores a 4.0, usado en SquirrelMail, permite a usuarios locales ganar privilegios de root mediante un nombre de usuario largo. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phppass | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands via the (1) uid and (2) pwd parameters. | |
| Modificada | Media (5) | 1.3% | — | Coffeecup Software Coffeecup Password Wizard | 31/12/2003 | 16/6/2026 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | |
| Modificada | Alta (7.2) | 0.30% | — | Bogofilter Bogopass Email Filter | 31/12/2002 | 16/6/2026 | bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. | |
| Modificada | Media (4) | 5.8% | — | Phpsquidpass | 31/12/2002 | 16/6/2026 | phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Chetcpasswd | 31/12/2002 | 16/6/2026 | chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field. | |
| Modificada | Media (6.2) | 0.29% | — | Chetcpasswd | 31/12/2002 | 16/6/2026 | Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639. | |
| Modificada | Media (6.2) | 0.27% | — | Chetcpasswd | 31/12/2002 | 16/6/2026 | Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors. |