Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. | |
| Modificada | Media (5.1) | 1.3% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. | |
| Modificada | Media (5) | 3.7% | — | Nrl.navy One-time Passwords IN Everything | 31/12/2001 | 16/6/2026 | One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist. | |
| Modificada | Media (4.6) | 0.35% | — | Counterpane Password Safe | 13/9/2001 | 16/6/2026 | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory… | |
| Modificada | Media (5) | 1.2% | 💥 Exploit | Passwd | 4/6/2000 | 16/6/2026 | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | |
| Modificada | Alta (7.2) | 0.40% | — | Linux-nis Rpc.yppasswdd | 23/10/1999 | 16/6/2026 | Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation. | |
| Modificada | Alta (10) | 1.6% | — | Quakenbush NT Password AppraiserAI | 1/1/1999 | 16/6/2026 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. | |
| Modificada | Media (6.4) | 1.1% | — | Ipass Roamserver | 29/12/1997 | 16/6/2026 | iPass RoamServer 3.1 creates temporary files with world-writable permissions. |