Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

336 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.24%—WP Edit Password ProtectedAI2/10/20262/10/2026
The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to read the content of published posts and pages that the site's access mode was configured to hide.
AplazadaMedia (5.5)0.32%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC…
AplazadaAlta (7.2)0.46%—Storeapps Temporary Login Without PasswordAI12/9/202614/9/2026
The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing…
AplazadaAlta (8)0.23%—Bulk Password ResetAI10/9/202610/9/2026
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a…
AplazadaAlta (8.7)0.37%—PasswordpusherAI9/9/202610/9/2026
PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is…
AplazadaMedia (5.3)0.21%—WP Edit Password ProtectedAI2/9/20263/9/2026
The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
Pendiente de análisisAlta (8.8)1.4%—Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI2/9/20268/9/2026
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
AplazadaCrítica (9.3)0.63%—Teampasswordmanager Team Password ManagerAI1/9/202623/9/2026
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
AplazadaBaja (1.9)1.1%—Sworddut Mcp-ffmpeg-helperAI24/8/202626/8/2026
A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of the argument format results in os command injection. Attacking locally is a requirement. The exploit is now public…
AplazadaMedia (6.9)1.1%—PasswordpusherAI22/8/202623/9/2026
PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true, so the check passes and the…
Pendiente de análisisMedia (6.9)0.14%—ARM HDD PasswordAI19/8/202631/8/2026
On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
AplazadaBaja (1.3)0.39%—Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI17/8/202620/8/2026
A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level…
Pendiente de análisisAlta (8.8)1.4%—Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Pendiente de análisisAlta (8.8)3.1%—Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
AplazadaAlta (8.1)0.75%—Ventraconnect Social Login Passwordless LoginAI12/8/202612/8/2026
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me…
AplazadaAlta (7.5)0.44%—Wpexperts Password ProtectedAI7/8/202626/8/2026
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content…
AnalizadaAlta (7.4)0.13%—Devolutions Password Manager29/7/202621/8/2026
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
AplazadaAlta (8.8)0.51%—WP Password PolicyAI28/7/202629/7/2026
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the…
AplazadaAlta (7.5)0.49%—Crypt PasswordAI20/7/202620/7/2026
Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.
AplazadaCrítica (9.8)0.55%—Crypt-passwordAI20/7/202620/7/2026
Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
AplazadaAlta (8.7)0.41%—PasswordpusherAI13/7/202615/7/2026
PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without triggering any push-level defense,…
AplazadaMedia (6.3)0.33%—PasswordpusherAI8/7/202614/7/2026
PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can create malicious pushes containing data:text/html URIs that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the…
Pendiente de análisisMedia (6.7)0.18%—Hypr PasswordlessAI25/6/202625/6/2026
Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1.
AplazadaMedia (4.3)0.13%—Andy Moyle Emergency Password ResetAI17/6/20261/10/2026
Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0.
AplazadaAlta (7.4)0.26%—Avira Password ManagerAIMozilla FirefoxAI12/6/202623/7/2026
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when used with Mozilla…