Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.52% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Crítica (9.8) | 0.53% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Crítica (9.8) | 0.69% | — | HPE Autopass License Server | 16/7/2025 | 17/6/2026 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18. | |
| Analizada | Crítica (10) | 68% | ⚠ Explotación activa | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Media (4.1) | 0.42% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to improper enforcement of access controls that are configured… | |
| Analizada | Alta (7.2) | 19% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Analizada | Alta (7.2) | 9.9% | — | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 16/7/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of user-supplied input. An attacker with valid credentials could exploit this… | |
| Aplazada | Alta (7.6) | 0.20% | — | Oneidentity Password ManagerAI | 14/7/2025 | 17/6/2026 | The Secure Password extension in One Identity Password Manager before 5.14.4 allows local privilege escalation. The issue arises from a flawed security hardening mechanism within the kiosk browser used to display the Password Self-Service site to end users. Specifically, the application attempts to restrict privileged… | |
| Analizada | Alta (7.5) | 0.42% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (7.5) | 0.42% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (8) | 0.43% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (7.3) | 1.3% | — | HPE Autopass License Server | 14/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17. | |
| Analizada | Alta (7.8) | 0.16% | — | Canonical Multipass | 12/7/2025 | 17/6/2026 | In Canonical Multipass up to and including version 1.15.1 on macOS, incorrect default permissions allow a local attacker to escalate privileges by modifying files executed with administrative privileges by a Launch Daemon during system startup. | |
| Analizada | Alta (7.8) | 0.17% | — | Trendmicro Password Manager | 10/7/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation. | |
| Analizada | Crítica (10) | 39% | 💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is due a lack of file validation checks that would prevent… | |
| Analizada | Crítica (10) | 98% | ⚠ Explotación activa💥 Exploit | Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector | 25/6/2025 | 17/6/2026 | A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation… | |
| Analizada | Crítica (9.3) | 0.57% | — | Esaqa Psono ClientBitdefender Securepass | 21/6/2025 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability has been identified in Psono-Client’s handling of vault entries of type website_password and bookmark, as used in Bitdefender SecurePass. The client does not properly sanitize the URL field in these entries. As a result, an attacker can craft a malicious vault entry (or trick… | |
| Analizada | Media (4.8) | 0.28% | — | Anujk305 BUS Pass Management System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulation of the argument profile name leads to cross site scripting. The… | |
| Analizada | Media (6.6) | 0.22% | — | Trendmicro Password Manager | 17/6/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password… | |
| Analizada | Baja (2.1) | 0.37% | — | Phpgurukul Rail Pass Management System | 16/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has… | |
| Analizada | Baja (1.9) | 0.29% | — | Phpgurukul Rail Pass Management System | 16/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2) | 0.30% | — | Phpgurukul Rail Pass Management System | 10/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/add-pass.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.42% | — | Phpgurukul Rail Pass Management System | 10/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /rpms/download-pass.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Aplazada | Alta (8.8) | 0.58% | — | Miniorange Password Policy ManagerAI | 9/6/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects Password Policy Manager: from n/a through <= 2.0.4. | |
| Aplazada | Media (4.3) | 0.15% | — | Hasina77 WP Easy AllopassAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hasina77 Wp Easy Allopass wordpress-easy-allopass allows Cross Site Request Forgery.This issue affects Wp Easy Allopass: from n/a through <= 4.1.1. |