Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Bedevious Password Reset With Code FOR Wordpress Rest API | 7/12/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15. | |
| Modificada | Alta (8.8) | 0.37% | — | Plainviewplugins Plainview Protect Passwords | 18/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in edward_plainview Plainview Protect Passwords.This issue affects Plainview Protect Passwords: from n/a through 1.4. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.1) | 0.40% | — | Plainviewplugins Plainview Protect Passwords | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in edward_plainview Plainview Protect Passwords plugin <= 1.4 versions. | |
| Modificada | Media (4.7) | 0.44% | — | Clickstudios Passwordstate | 13/11/2023 | 17/6/2026 | An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to… | |
| Modificada | Alta (8.8) | 0.30% | — | Shawfactor Lh-password-changer | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Peter Shaw LH Password Changer plugin <= 1.55 versions. | |
| Modificada | Baja (3.5) | 0.24% | — | Clickstudios Passwordstate | 31/10/2023 | 17/6/2026 | Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request. | |
| Modificada | Media (5.3) | 0.51% | — | Mendix Forgot Password | 10/10/2023 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All versions < V5.4.0), Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.3), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.3), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.4.0).… | |
| Modificada | Media (6.1) | 23% | — | Pleasantsolutions Pleasant Password Server | 4/10/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the component /framework/cron/action/humanize of Pleasant Solutions Pleasant Password Server v7.11.41.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cronString parameter. | |
| Modificada | Media (6.8) | 0.54% | — | Oneidentity Password Manager | 27/9/2023 | 17/6/2026 | One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges. | |
| Modificada | Alta (7.5) | 0.67% | — | Password Recovery Project Password Recovery | 4/9/2023 | 17/6/2026 | Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has… | |
| Modificada | Media (5.3) | 0.61% | — | Password Recovery Project Password Recovery | 4/9/2023 | 17/6/2026 | User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could allow a remote attacker to create a test script against the password recovery function to enumerate all users in the database. | |
| Modificada | Media (4.8) | 0.44% | — | Davidsword Mobile Call NOW & MAP Buttons | 30/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davidsword Mobile Call Now & Map Buttons plugin <= 1.5.0 versions. | |
| Modificada | Media (6.1) | 3.1% | — | Zohocorp Manageengine Password Manager PRO | 11/8/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload. | |
| Modificada | Media (4.8) | 0.40% | — | Wpexperts Password Protected | 23/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions. | |
| Modificada | Alta (7.8) | 0.47% | — | Soft-o Free Password Manager | 12/5/2023 | 17/6/2026 | A DLL Hijacking issue discovered in Soft-o Free Password Manager 1.1.20 allows attackers to create arbitrary DLLs leading to code execution. | |
| Modificada | Media (4.9) | 0.90% | — | Changingtec Mobile ONE Time Password | 27/4/2023 | 17/6/2026 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files. | |
| Modificada | Alta (7.8) | 0.81% | — | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO | 26/4/2023 | 17/6/2026 | Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to… | |
| Modificada | Media (5.3) | 0.46% | — | Mendix Forgot Password | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1), Mendix Forgot Password (Mendix 9 compatible) (All versions < V5.1.1). The affected versions of the module contain an observable response… | |
| Modificada | Media (5.4) | 0.65% | — | Passwordprotectwp Password Protect Wordpress | 6/2/2023 | 17/6/2026 | The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Crítica (9.8) | 71% | — | Zohocorp Manageengine Password Manager PROZohocorp Manageengine Pam360Zohocorp Manageengine Access Manager Plus | 5/1/2023 | 17/6/2026 | Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection. | |
| Modificada | Media (6.1) | 3.8% | 💥 Exploit | Adiscon Password Manager FOR IIS | 26/12/2022 | 17/6/2026 | Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | |
| Modificada | Media (6.5) | 0.75% | — | Clickstudios Passwordstate | 19/12/2022 | 17/6/2026 | A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the component Browser Extension Provisioning. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit… | |
| Modificada | Media (6.5) | 0.88% | — | Clickstudios Passwordstate | 19/12/2022 | 17/6/2026 | A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The manipulation leads to insufficiently protected credentials. The attack can be initiated remotely. The exploit has been disclosed to the… |