Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.22%—Bizswoop Account Manager FOR WoocommerceAI27/5/202617/6/2026
Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCommerce: from n/a through 2.1.2.
AnalizadaAlta (8.8)0.77%—Ldap-account-manager Ldap Account Manager18/3/202617/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, the PDF export component does not correctly validate uploaded file extensions. This way any file type (including .php files) can be uploaded. With GHSA-w7xq-vjr3-p9cf,…
AnalizadaAlta (8.8)0.67%—Ldap-account-manager Ldap Account Manager18/3/202617/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. Prior to version 9.5, a local file inclusion was detected in the PDF export that allows users to include local PHP files and this way execute code. In combination with GHSA-88hf-2cjm-m9g8…
AplazadaMedia (4.6)0.17%—Ldap-account-manager Ldap Account ManagerAI16/9/202517/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM before 9.3 allows stored cross-site scripting in the Profile section via the profile name field, which renders untrusted input as HTML and executes a supplied script (for example a script element). An authenticated user…
AplazadaMedia (6.5)0.70%—Ldap-account-manager Ldap Account ManagerAI17/12/202417/6/2026
LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In affected versions LAM does not properly sanitize configuration values, that are set via `mainmanage.php` and `confmain.php`. This allows setting arbitrary config values and thus…
AnalizadaMedia (6.6)18%—Ldap-account-manager Ldap Account Manager18/3/202417/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries stored in an LDAP directory. LAM's log configuration allows to specify arbitrary paths for log files. Prior to version 8.7, an attacker could exploit this by creating a PHP file and cause LAM to log some PHP code to this file. When the file is then…
AnalizadaAlta (7.5)0.70%—Opentext Netiq Privileged Account Manager13/3/202417/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2.
AnalizadaAlta (7.5)0.55%—Prestaworld Account Manager3/3/202417/6/2026
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods.
AnalizadaAlta (7.5)0.58%—Prestaworld Account Manager27/2/202417/6/2026
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
ModificadaMedia (6.1)0.52%—Pingidentity Self-service Account Manager10/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Ping Identity Self-Service Account Manager 1.1.2. Affected by this issue is some unknown functionality of the file src/main/java/com/unboundid/webapp/ssam/SSAMController.java. The manipulation leads to cross site scripting. The attack may be…
ModificadaMedia (5.3)1.3%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the user name field at login could be used to enumerate LDAP data. This is only the case for LDAP search configuration. This issue has been fixed in version 8.0.
ModificadaAlta (7.8)0.44%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An attacker capable of writing files under…
ModificadaAlta (8.8)2.3%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 incorrect regular expressions allow to upload PHP scripts to config/templates/pdf. This vulnerability could lead to a Remote Code Execution if the…
ModificadaMedia (6.1)0.27%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration.…
ModificadaAlta (8.1)2.5%—Ldap-account-manager Ldap Account ManagerDebian Linux27/6/202217/6/2026
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 There are cases where LAM instantiates objects from arbitrary classes. An attacker can inject the first constructor argument. This can lead to code execution if…
ModificadaMedia (4.8)1.1%—Ldap-account-manager Ldap Account ManagerDebian Linux15/4/202217/6/2026
LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated user can store XSS payloads in the…
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
ModificadaMedia (6.1)1.6%—Ldap-account-manager Ldap Account ManagerDebian LinuxFedoraproject Fedora5/12/201916/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
ModificadaAlta (8.8)1.3%—Debian LinuxLdap-account-manager Ldap Account Manager27/3/201817/6/2026
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.
ModificadaMedia (6.1)1.5%—Debian LinuxLdap-account-manager Ldap Account Manager27/3/201817/6/2026
Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.
ModificadaCrítica (9.8)1.4%—Netiq Privileged Account Manager6/3/201817/6/2026
PAM exposure enabling unauthenticated access to remote host
ModificadaMedia (6.1)0.75%—Netiq Privileged Account Manager5/3/201817/6/2026
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
ModificadaMedia (6.1)0.61%—Netiq Privileged Account Manager2/3/201817/6/2026
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.
ModificadaMedia (5.4)0.27%—Ford Credit Account Manager2/10/201417/6/2026
The Ford Credit Account Manager (aka com.fordcredit.accountmanager) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.4%—Ldap-account-manager Ldap Account Manager5/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.