Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.68%—Zx2c4 Password-store9/12/202017/6/2026
pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the password. If an attacker controls the central Git server or one of the other members' machines, and also controls one…
ModificadaMedia (4.6)0.41%—Lock Password Manager Safe APP Project Lock Password Manager Safe APP30/11/202017/6/2026
The Estil Hill Lock Password Manager Safe app 2.3 for iOS has a *#06#* backdoor password. An attacker with physical access can unlock the password manager without knowing the master password set by the user.
ModificadaMedia (5.3)0.87%—Oneidentity Password Manager13/11/202017/6/2026
An issue was discovered in One Identity Password Manager 5.8. An attacker could enumerate valid answers for a user. It is possible for an attacker to detect a valid answer based on the HTTP response content, and reuse this answer later for a password reset on a chosen password. The enumeration is possible because,…
ModificadaAlta (7.5)1.1%—Microfocus Self Service Password Reset5/11/202017/6/2026
Sensitive information disclosure vulnerability in Micro Focus Self Service Password Reset (SSPR) product. The vulnerability affects versions 4.4.0.0 to 4.4.0.6 and 4.5.0.1 and 4.5.0.2. In certain configurations the vulnerability could disclose sensitive information.
ModificadaMedia (6.8)1.1%💥 PoCClickstudios Passwordstate29/10/202017/6/2026
An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built-in generator (4 digits), a remote attacker has the opportunity to conduct a brute force attack on this PIN code. As result, remote attacker…
ModificadaCrítica (9.8)0.87%—1password Command Line Interface1password Scim27/10/202017/6/2026
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force…
ModificadaCrítica (9.6)1.2%—Antsword Project Antsword26/10/202017/6/2026
A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
ModificadaMedia (6.1)1.3%—Antsword Project Antsword26/10/202017/6/2026
AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.
ModificadaAlta (7.5)5.1%💥 PoCClickstudios Passwordstate5/10/202017/6/2026
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the…
ModificadaAlta (8.8)1.9%💥 PoCAnixis Password Reset Client30/9/20209/7/2026
The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of…
ModificadaCrítica (9.8)1.4%—Alfresco Reset Password18/9/202017/6/2026
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0
ModificadaAlta (8.8)1.0%—Alfresco Reset Password17/9/202017/6/2026
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
ModificadaAlta (7.5)0.92%—Flexsolution Reset Password17/9/202017/6/2026
The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.
ModificadaMedia (5.9)0.97%—Vipre Password Vault22/6/202017/6/2026
The ThreatTrack VIPRE Password Vault app through 1.100.1090 for iOS has Missing SSL Certificate Validation.
ModificadaAlta (8.4)0.36%—Toshiba Password Tool FOR Windows20/4/202017/6/2026
An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20TY, HD-MA20TY, HD-MB20TS, HD-MA20TS), CANVIO PREMIUM 1TB(HD-MB10TY, HD-MA10TY, HD-MB10TS,…
ModificadaAlta (7.5)1.2%—Django-nopassword Project Django-nopassword18/3/202017/6/2026
django-nopassword before 5.0.0 stores cleartext secrets in the database.
ModificadaCrítica (9.8)7.8%—Zohocorp Manageengine Password Manager PRO16/3/202017/6/2026
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be provided by an external application, and do…
ModificadaAlta (8.8)2.2%—Zohocorp Manageengine Password Manager PRO16/3/202017/6/2026
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
ModificadaMedia (5.4)0.54%—Teampasswordmanager Team Password Manager16/3/202017/6/2026
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
ModificadaAlta (7.8)0.46%—Trendmicro Password Manager12/3/202017/6/2026
Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.
ModificadaMedia (6.5)4.4%—Zohocorp Manageengine Password Manager PRO9/3/202017/6/2026
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
ModificadaAlta (8.6)1.5%—Yubico Yubikey ONE Time Password Validation Server5/3/202017/6/2026
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool; the issue does NOT affect YubiCloud.
ModificadaAlta (7.5)1.5%—Yubico Yubikey ONE Time Password Validation Server5/3/202017/6/2026
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service; the issue does NOT…
ModificadaMedia (5.5)0.47%—Trendmicro Password Manager18/1/202017/6/2026
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.
ModificadaMedia (5.5)0.98%—Trendmicro Password Manager18/1/202017/6/2026
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
Orbitaley — Vulnerabilidades