Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2)0.25%—Projectworlds Gate Pass Management System27/10/202517/6/2026
A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (3.7)0.31%—Wpexperts Password ProtectedAI25/10/202517/6/2026
The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7.11. This is due to the plugin trusting client-controlled HTTP headers (such as X-Forwarded-For, HTTP_CLIENT_IP, and similar headers) to determine user IP addresses in the…
AplazadaMedia (4.3)0.20%—Miniorange Password Policy ManagerAI25/10/202530/9/2026
The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'moppm_ajax' AJAX endpoint in all versions up to, and including, 2.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaAlta (7.1)0.30%—Calvaweb Password Only LoginAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Calvaweb Password only login password-only-login allows Reflected XSS.This issue affects Password only login: from n/a through <= 0.2.
AplazadaCrítica (9.8)0.79%💥 PoCOwnid Passwordless LoginAI15/10/202517/6/2026
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (6.7)0.14%—Siemens Sipass Integrated14/10/202517/6/2026
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords. Successful exploitation of this vulnerability allows…
AnalizadaMedia (5.1)0.20%—Siemens Sipass Integrated14/10/202517/6/2026
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an…
AnalizadaAlta (7)0.32%—Siemens Sipass Integrated14/10/202517/6/2026
A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation allows an…
AnalizadaMedia (5.5)0.43%—Projectworlds Gate Pass Management System9/10/202517/6/2026
A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argument fullname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AnalizadaAlta (7.5)0.40%—Arandasoft Passrecovery26/9/202517/6/2026
An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.
AplazadaMedia (6.5)0.22%💥 PoCWpchill PasssterAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Passster content-protector allows Stored XSS.This issue affects Passster: from n/a through <= 4.2.18.
AplazadaMedia (4.3)0.17%—Andy Moyle Emergency Password ResetAI22/9/202530/9/2026
Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Emergency Password Reset emergency-password-reset allows Cross Site Request Forgery.This issue affects Emergency Password Reset: from n/a through <= 9.3.
AplazadaMedia (5.3)0.23%—Secure PasskeysAI20/9/202517/6/2026
The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and…
AplazadaCrítica (9.8)0.24%—Bedevious Password Reset With Code FOR Wordpress Rest APIAI18/9/202517/6/2026
The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound algorithms to generate OTP codes, potentially leading to account takeovers.
AplazadaBaja (3.2)0.15%—Clickstudios PasswordstateAI16/9/202530/9/2026
Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section.
AplazadaMedia (6.1)0.22%—WP Edit Password ProtectedAI11/9/202517/6/2026
The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
AplazadaMedia (6.5)0.21%—Marcshowpass ShowpassAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in marcshowpass Showpass WordPress Extension showpass allows Stored XSS.This issue affects Showpass WordPress Extension: from n/a through <= 4.0.3.
AplazadaAlta (7.5)0.11%—HCL CompassAI3/9/202530/9/2026
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
AplazadaAlta (7.3)0.34%—Opentext Self Service Password ResetAI29/8/202517/6/2026
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Authentication Bypass.This issue affects Self Service Password Reset from before 4.8 patch 3.
AplazadaAlta (7.1)0.24%—Themepassion Support TicketAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Support Ticket support-ticket allows Reflected XSS.This issue affects Support Ticket: from n/a through <= 1.9.
AplazadaCrítica (9.8)0.45%—Themepassion Support TicketAI20/8/202517/6/2026
Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.This issue affects Support Ticket: from n/a through <= 1.9.
AplazadaAlta (7.1)0.24%—Themepassion Ultra PortfolioAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themepassion Ultra Portfolio ultra-portfolio allows Reflected XSS.This issue affects Ultra Portfolio: from n/a through <= 6.7.
AnalizadaMedia (6.5)0.32%—Passwordprotectwp Password Protect Wordpress14/8/202517/6/2026
The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a password authorization, however users with subscriber or greater roles can view content via the REST API.
AplazadaMedia (6.9)0.39%—Thinbus Javascript Secure Remote PasswordAI7/8/202517/6/2026
Thinbus Javascript Secure Remote Password is a browser SRP6a implementation for zero-knowledge password authentication. In versions 2.0.0 and below, a protocol compliance bug causes the client to generate a fixed 252 bits of entropy instead of the intended bit length of the safe prime (defaulted to 2048 bits). The…
AnalizadaAlta (7.5)0.51%—Rosenpass28/7/202517/6/2026
The rosenpass crate before 0.2.1 for Rust allows remote attackers to cause a denial of service (panic) via a one-byte UDP packet.
Orbitaley — Vulnerabilidades