Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2597▼ 310 respecto a la semana anterior
Críticas / altas1338▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 2.5% | — | WEB PasswdAI | 13/5/2026 | 17/6/2026 | Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated or escaped, and is used as the last argument on the command line, allowing for command injection. | |
| Aplazada | Alta (7.5) | 0.51% | — | Crypt Passwd MD5AI | 8/5/2026 | 17/6/2026 | Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography. | |
| Modificada | Media (4.8) | 0.39% | — | WP Htpasswd Project WP Htpasswd | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Matteo Candura WP htpasswd plugin <= 1.7 versions. | |
| Modificada | Alta (7.5) | 0.67% | — | Squirrelmail Change Passwd | 13/2/2020 | 16/6/2026 | Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords. | |
| Modificada | Alta (7.5) | 1.3% | — | Makepasswd Project Makepasswd | 6/11/2019 | 16/6/2026 | makepasswd 1.10 default settings generate insecure passwords | |
| Modificada | Media (4.3) | 5.1% | — | Horde Passwd | 8/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Chetcpasswd | 21/12/2006 | 16/6/2026 | Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a dictionary attack. | |
| Modificada | Alta (7.5) | 3.0% | — | Pedro Lineu Orso Chetcpasswd | 21/12/2006 | 16/6/2026 | Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd before 2.4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long X-Forwarded-For HTTP header. NOTE: The provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (7.8) | 1.4% | — | Pedro Lineu Orso Chetcpasswd | 21/12/2006 | 16/6/2026 | Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the PAM configuration, which might allow remote attackers to bypass intended restrictions implemented through PAM. | |
| Modificada | Media (5) | 2.0% | — | Chetcpasswd Project Chetcpasswd | 21/12/2006 | 16/6/2026 | Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system. | |
| Modificada | Alta (7.2) | 0.42% | — | Pedro Lineu Orso Chetcpasswd | 21/12/2006 | 16/6/2026 | Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 2.1% | — | Chetcpasswd Project Chetcpasswd | 21/12/2006 | 16/6/2026 | Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header. | |
| Modificada | Media (4.6) | 0.32% | — | Chetcpasswd | 21/12/2006 | 16/6/2026 | Pedro Lineu Orso chetcpasswd before 2.3.1 does not document the need for 0400 permissions on /etc/chetcpasswd.allow, which might allow local users to gain sensitive information by reading this file. | |
| Modificada | Media (4.6) | 0.31% | — | Chetcpasswd | 19/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in chetcpasswd 2.4.1 allow local users to gain privileges via unspecified vectors related to executing (1) the cp program, (2) the mail program, or (3) the program specified in the post_change configuration line. | |
| Modificada | Media (4.6) | 0.80% | — | Thiago Melo DE Paula Change Passwd | 21/1/2006 | 16/6/2026 | Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Passwd | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title. | |
| Modificada | Media (4.6) | 1.5% | — | Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+7 | 31/12/2004 | 16/6/2026 | Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not… | |
| Modificada | Alta (7.2) | 0.42% | — | PasswdAILinux-pamAI | 31/12/2004 | 16/6/2026 | passwd 0.68 does not check the return code for the pam_start function, which has unknown impact and attack vectors that may prevent "safe and proper operation" of PAM. | |
| Modificada | Alta (10) | 4.6% | — | Squirrelmail Change Passwd PluginAI | 6/8/2004 | 16/6/2026 | Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local users to gain root privileges via a long user name. | |
| Modificada | Alta (7.5) | 6.4% | — | Chetcpasswd | 31/12/2002 | 16/6/2026 | chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow file via a long user (userid) field. | |
| Modificada | Media (6.2) | 0.29% | — | Chetcpasswd | 31/12/2002 | 16/6/2026 | Untrusted search path vulnerability in Pedro Lineu Orso chetcpasswd 2.4.1 and earlier allows local users to gain privileges via a modified PATH that references a malicious cp binary. NOTE: this issue might overlap CVE-2006-6639. | |
| Modificada | Media (6.2) | 0.27% | — | Chetcpasswd | 31/12/2002 | 16/6/2026 | Buffer overflow in Pedro Lineu Orso chetcpasswd before 1.12, when configured for access from 0.0.0.0, allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Passwd | 4/6/2000 | 16/6/2026 | PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords. | |
| Modificada | Alta (7.2) | 0.40% | — | Linux-nis Rpc.yppasswdd | 23/10/1999 | 16/6/2026 | Buffer overflow in rpc.yppasswdd allows a local user to gain privileges via MD5 hash generation. |