Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.32%—Microfocus Netiq Self Service Password Reset21/8/202417/6/2026
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6
AnalizadaAlta (7.8)0.31%—1password6/8/202417/6/2026
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
AnalizadaMedia (4.7)0.20%—1password6/8/202417/6/2026
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
AnalizadaAlta (8.5)0.33%—Itopvpn Dualsafe Password Manager31/7/202417/6/2026
A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was…
AplazadaAlta (7.2)0.59%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
AplazadaMedia (4.9)0.61%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
AplazadaMedia (6.5)0.31%—Clickstudios PasswordstateAI24/6/202417/6/2026
Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass.
AnalizadaMedia (4.9)0.41%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
AnalizadaBaja (2.7)0.27%—Beyondtrust Beyondinsight Password Safe11/6/202417/6/2026
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
AplazadaMedia (5.6)0.11%—Hypr PasswordlessAI21/5/202417/6/2026
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
AplazadaAlta (7.8)0.72%—Watchguard Authpoint Password ManagerAI16/5/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for…
AplazadaMedia (4.3)0.34%—Wpexperts Password ProtectedAI15/5/202417/6/2026
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract…
AplazadaAlta (7.5)0.57%—Counterpane PasswordsafeAI6/5/202417/6/2026
Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.
AplazadaAlta (7.1)0.33%—Jojaba Access Category PasswordAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jojaba Access Category Password allows Reflected XSS.This issue affects Access Category Password: from n/a through 1.5.1.
AnalizadaAlta (8.8)0.57%—Enpass Password Manager10/4/202417/6/2026
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
AplazadaBaja (2.2)0.09%—Kaspersky Password ManagerAIGoogle ChromeAI22/3/202417/6/2026
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker must trick a user into visiting a login form of a website with the…
AnalizadaAlta (7.1)0.24%—Itopvpn Dualsafe Password Manager21/3/202417/6/2026
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.
AplazadaMedia (6.5)0.33%—Cozmoslabs Passwordless LoginAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.
ModificadaMedia (5.3)0.57%—Rajkakadiya Password Protected Store FOR Woocommerce5/3/202417/6/2026
The Password Protected Store for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the REST API. This makes it possible for unauthenticated attackers to extract sensitive data including post titles and content.
ModificadaMedia (4.8)0.34%—Wpexperts Password Protected29/2/202417/6/2026
The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Captcha Site Key in all versions up to, and including, 2.6.6 due to insufficient input sanitization and output escaping. This makes it possible…
ModificadaMedia (5.3)0.48%—Passwordprotectwp Password Protect Wordpress29/2/202417/6/2026
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.9 via API. This makes it possible for unauthenticated attackers to obtain post titles, IDs, slugs as well as other information including for password-protected posts.
ModificadaAlta (8.8)0.52%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: wait for a session timeout, click…
ModificadaCrítica (9.8)1.0%—Oneidentity Password Manager25/12/202317/6/2026
One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape sequence is: go to the Google ReCAPTCHA…
ModificadaCrítica (9.8)1.2%—Ltb-project Self Service Password21/12/202317/6/2026
An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.
ModificadaMedia (4.8)0.39%—Andreasmuench Multiple Post Passwords14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andreas Münch Multiple Post Passwords allows Stored XSS.This issue affects Multiple Post Passwords: from n/a through 1.1.1.
Orbitaley — Vulnerabilidades