Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6)0.50%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector15/4/202625/9/2026
A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root. This…
Pendiente de análisisAlta (7.3)0.19%—KeepassxcAIOpensslAI11/4/202617/6/2026
KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of KeePassXC. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.1)0.40%—Laravel Passport9/4/202617/6/2026
Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Bypass for client_credentials tokens. the league/oauth2-server library sets the JWT sub claim to the client identifier (since there's no user). The token guard then passes this value to retrieveById()…
AnalizadaCrítica (9.3)0.23%—Teampass31/3/202617/6/2026
Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript…
AnalizadaCrítica (9.3)0.27%—Teampass31/3/202617/6/2026
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in…
AnalizadaAlta (8.6)0.25%—Passfab Excel Password Recovery26/3/202617/6/2026
PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that…
AnalizadaAlta (8.6)0.21%—Passfab RAR Password Recovery26/3/202617/6/2026
PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail…
AnalizadaMedia (6.8)0.18%—Passfab Excel Password Recovery26/3/202617/6/2026
Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration…
AplazadaAlta (7.1)0.18%—Themepassion Legacy AdminAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Legacy Admin legacy-admin allows Reflected XSS.This issue affects Legacy Admin: from n/a through <= 9.5.
AplazadaAlta (7.1)0.18%—Themepassion Ultra Wordpress AdminAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra WordPress Admin ultra-admin allows Reflected XSS.This issue affects Ultra WordPress Admin: from n/a through <= 11.7.
AplazadaMedia (6.9)0.12%—RAR Password RecoveryAI11/3/202617/6/2026
RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger…
AplazadaMedia (6.9)0.12%—Outlook Password RecoveryAI11/3/202617/6/2026
Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of…
AplazadaMedia (6.9)0.12%—SQL Server Password ChangerAI11/3/202617/6/2026
SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.
AplazadaMedia (6.9)0.13%—Spotie Internet Explorer Password RecoveryAI11/3/202617/6/2026
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a…
AnalizadaMedia (6.5)0.17%—Lesspass9/3/202617/6/2026
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspass lesspass v9.6.9 which allows attackers to obtain sensitive information.
AnalizadaCrítica (10)0.98%—HPE Autopass License Server2/3/202610/8/2026
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
AplazadaMedia (6.5)0.26%—Passionatebrains Advance WC AnalyticsAI20/2/202617/6/2026
Missing Authorization vulnerability in Passionate Brains Advanced WC Analytics advance-wc-analytics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced WC Analytics: from n/a through <= 3.19.0.
AplazadaMedia (6.5)0.26%—Passionatebrains Ga4wp Google Analytics FOR WordpressAI20/2/202617/6/2026
Missing Authorization vulnerability in Passionate Brains GA4WP: Google Analytics for WordPress ga-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GA4WP: Google Analytics for WordPress: from n/a through <= 2.10.0.
AplazadaAlta (7.8)0.15%—HPE Aruba Networking Clearpass OnguardAI18/2/202617/6/2026
A local privilege-escalation vulnerability has been discovered in the HPE Aruba Networking ClearPass OnGuard Software for Linux. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges.
ModificadaAlta (7.1)0.48%—Kostasmitroglou Password Management Application12/2/202617/6/2026
thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts.
ModificadaAlta (7.1)0.48%—Kostasmitroglou Password Management Application12/2/202617/6/2026
TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information.
AplazadaMedia (4.6)0.25%—MSN Password RecoveryAI11/2/202617/6/2026
MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to…
AplazadaMedia (4.6)0.41%—Krylack ZIP Password RecoveryAI11/2/202617/6/2026
ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file.
AplazadaMedia (6.7)0.22%—MSN Password RecoveryAI11/2/202617/6/2026
MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration…
AplazadaMedia (4.6)0.30%—TOP Password Software Dialup Password RecoveryAI11/2/202617/6/2026
Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields.
Orbitaley — Vulnerabilidades