Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | Social Login Passkeys Magic Link Email OTPAI | 20/7/2026 | 21/7/2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email… | |
| Analizada | Media (5.5) | 0.50% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/7/2026 | 25/9/2026 | This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | |
| Aplazada | Alta (8.7) | 0.41% | — | PasswordpusherAI | 13/7/2026 | 15/7/2026 | PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense,… | |
| Aplazada | Media (6.8) | 0.15% | — | Samsung PassAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. | |
| Aplazada | Alta (8.2) | 0.35% | — | Peakup Technology INC PassgateAI | 9/7/2026 | 9/7/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Injection. This issue affects PassGate: through 30042026. | |
| Aplazada | Media (6.3) | 0.33% | — | PasswordpusherAI | 8/7/2026 | 14/7/2026 | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the… | |
| Pendiente de análisis | Media (6.7) | 0.18% | — | Hypr PasswordlessAI | 25/6/2026 | 25/6/2026 | Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1. | |
| Analizada | Alta (7.5) | 0.50% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected… | |
| Analizada | Crítica (9.1) | 8.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 17/6/2026 | 25/9/2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of… | |
| Aplazada | Media (4.3) | 0.13% | — | Andy Moyle Emergency Password ResetAI | 17/6/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0. | |
| Aplazada | Alta (7.4) | 0.26% | — | Avira Password ManagerAIMozilla FirefoxAI | 12/6/2026 | 23/7/2026 | Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when used with Mozilla… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Akmer Informatics Automation Industry AND Trade TeknopassAI | 4/6/2026 | 22/7/2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429. | |
| Aplazada | Media (4.4) | 0.33% | — | Passeum TicketingAI | 3/6/2026 | 21/7/2026 | The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name` setting value without sanitization when it begins with "http", combined with insufficient validation in the… | |
| Aplazada | Alta (8.8) | 0.32% | — | Projectworlds Gate Pass Management SystemAI | 30/5/2026 | 22/7/2026 | Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to… | |
| Analizada | Alta (8.4) | 0.45% | — | Canonical Multipass | 28/5/2026 | 17/6/2026 | An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment bypass vulnerability within its validate_path function in src/sshfs_mount/sftp_server.cpp. The function performs a plain… | |
| Analizada | Alta (7.8) | 0.16% | — | Canonical Multipass | 28/5/2026 | 17/6/2026 | An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd daemon binary to root:wheel, five co-located binaries (multipass, qemu-img, qemu-system-aarch64, qemu-system-x86_64, and… | |
| Aplazada | Media (4.6) | 0.17% | — | Siber Systems Roboform Password ManagerAI | 20/5/2026 | 23/7/2026 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification. | |
| Analizada | Media (5.3) | 0.45% | — | Mongodb Compass | 20/5/2026 | 24/9/2026 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading to "1-click" command execution. | |
| Aplazada | Crítica (9.8) | 2.5% | — | WEB PasswdAI | 13/5/2026 | 17/6/2026 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. | |
| Aplazada | Alta (7.5) | 0.51% | — | Crypt Passwd MD5AI | 8/5/2026 | 17/6/2026 | Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. | |
| Analizada | Media (6.5) | 0.52% | — | Apnotic Password Pusher | 8/5/2026 | 17/6/2026 | Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Passmark BurnintestAIPassmark OsforensicsAIPassmark PerformancetestAI | 1/5/2026 | 17/6/2026 | An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 allows attackers to access kernel memory and escalate privileges via a crafted IOCTL 0x8011E044 call. | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Analizada | Media (4.9) | 6.5% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper… | |
| Analizada | Crítica (9.9) | 10% | — | Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine | 15/4/2026 | 25/9/2026 | A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… |