Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.83% | — | Jenkins Mask Passwords | 12/4/2022 | 17/6/2026 | Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (6.5) | 1.0% | — | Avira Password Manager | 12/4/2022 | 17/6/2026 | A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visited a page crafted by an attacker, the discovered vulnerability could trigger the Password Manager Extension to fill in the password field automatically. An attacker could then access this… | |
| Modificada | Media (6.5) | 0.82% | — | Clickstudios Passwordstate | 21/3/2022 | 17/6/2026 | In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticated user who has write permissions to a password list in one folder (with the default permission model) can extend his permissions to all… | |
| Modificada | Alta (7.8) | 0.68% | — | Trendmicro Password Manager | 8/3/2022 | 17/6/2026 | Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mendix Forgot Password | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to… | |
| Modificada | Crítica (9.8) | 0.97% | — | Mendix Forgot Password | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts. | |
| Modificada | Media (6.6) | 0.25% | — | Devolutions Password HUB | 3/3/2022 | 17/6/2026 | The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts. | |
| Modificada | Media (4.3) | 0.36% | — | Storeapps Temporary Login Without Password | 13/12/2021 | 17/6/2026 | The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them | |
| Modificada | Alta (7.8) | 0.34% | — | Kaspersky Password Manager | 23/11/2021 | 17/6/2026 | A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High. | |
| Modificada | Alta (7.5) | 0.79% | — | Teampasswordmanager Team Password Manager | 19/11/2021 | 17/6/2026 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning. | |
| Modificada | Alta (8.8) | 0.43% | — | Teampasswordmanager Team Password Manager | 19/11/2021 | 17/6/2026 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. | |
| Modificada | Media (5.4) | 1.0% | — | Antsword Redis Project Antsword Redis | 26/10/2021 | 17/6/2026 | AS_Redis is an AntSword plugin for Redis. The Redis Manage plugin for AntSword prior to version 0.5 is vulnerable to Self-XSS due to due to insufficient input validation and sanitization via redis server configuration. Self-XSS in the plugin configuration leads to code execution. This issue is patched in version 0.5. | |
| Modificada | Alta (7.8) | 0.42% | — | Krylack ZIP Password Recovery | 22/10/2021 | 17/6/2026 | Passcovery Co. Ltd ZIP Password Recovery v3.70.69.0 was discovered to contain a buffer overflow via the decompress function. | |
| Modificada | Media (6.5) | 0.93% | — | 1password | 29/9/2021 | 17/6/2026 | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items that would normally be fillable by the user on that web page. These… | |
| Modificada | Media (5.3) | 2.1% | — | Zohocorp Manageengine Password Manager PRO | 31/7/2021 | 17/6/2026 | Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid. | |
| Modificada | Alta (7.8) | 0.47% | — | 1password | 26/7/2021 | 17/6/2026 | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.47% | — | 1password Connect | 16/7/2021 | 17/6/2026 | 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be used to perform privilege escalation. Malicious users authorized to create Secrets Automation access tokens can create tokens that have access beyond what the user is authorized to… | |
| Modificada | Alta (8.8) | 5.2% | — | Trendmicro Password Manager | 8/7/2021 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit… | |
| Modificada | Alta (7.8) | 0.37% | — | Trendmicro Password Manager | 8/7/2021 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must first obtain the ability to execute… | |
| Modificada | Media (5.9) | 3.1% | — | Zohocorp Manageengine Password Manager PRO | 16/6/2021 | 17/6/2026 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types. | |
| Modificada | Alta (7.5) | 1.0% | — | Thycotic Password Reset Server | 11/6/2021 | 17/6/2026 | Thycotic Password Reset Server before 5.3.0 allows credential disclosure. | |
| Modificada | Alta (7.5) | 0.74% | — | Kaspersky Password Manager | 14/5/2021 | 17/6/2026 | Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation). | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Password Manager | 13/4/2021 | 17/6/2026 | Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program. | |
| Modificada | Alta (8.8) | 0.90% | — | Mendix Forgot Password | 15/3/2021 | 17/6/2026 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts. | |
| Modificada | Media (6.5) | 1.0% | — | 1password Scim Bridge | 8/2/2021 | 17/6/2026 | 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key. |