Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
336 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.17% | — | Siber Systems Roboform Password ManagerAI | 20/5/2026 | 23/7/2026 | Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor notification. | |
| Aplazada | Alta (8.8) | 0.45% | — | AntswordAI | 12/5/2026 | 17/6/2026 | AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vulnerability is fixed in 2.1.16. | |
| Analizada | Media (6.5) | 0.52% | — | Apnotic Password Pusher | 8/5/2026 | 17/6/2026 | Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain configurations. This could bypass the… | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Analizada | Alta (8.6) | 0.25% | — | Passfab Excel Password Recovery | 26/3/2026 | 17/6/2026 | PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that… | |
| Analizada | Alta (8.6) | 0.21% | — | Passfab RAR Password Recovery | 26/3/2026 | 17/6/2026 | PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail… | |
| Analizada | Media (6.8) | 0.18% | — | Passfab Excel Password Recovery | 26/3/2026 | 17/6/2026 | Excel Password Recovery Professional 8.2.0.0 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long string to the 'E-Mail and Registrations Code' field. Attackers can paste a crafted payload containing 5000 bytes of data into the registration… | |
| Aplazada | Media (6.9) | 0.12% | — | RAR Password RecoveryAI | 11/3/2026 | 17/6/2026 | RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger… | |
| Aplazada | Media (6.9) | 0.12% | — | Outlook Password RecoveryAI | 11/3/2026 | 17/6/2026 | Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of… | |
| Aplazada | Media (6.9) | 0.12% | — | SQL Server Password ChangerAI | 11/3/2026 | 17/6/2026 | SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition. | |
| Aplazada | Media (6.9) | 0.13% | — | Spotie Internet Explorer Password RecoveryAI | 11/3/2026 | 17/6/2026 | SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a… | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | thesystem App 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the username parameter. Attackers can inject malicious SQL code like ' or '1=1 to the username field to gain unauthorized access to user accounts. | |
| Modificada | Alta (7.1) | 0.48% | — | Kostasmitroglou Password Management Application | 12/2/2026 | 17/6/2026 | TheSystem 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating the 'server_name' parameter. Attackers can inject malicious SQL code like ' or '1=1 to retrieve unauthorized database records and potentially access sensitive system information. | |
| Aplazada | Media (4.6) | 0.25% | — | MSN Password RecoveryAI | 11/2/2026 | 17/6/2026 | MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to… | |
| Aplazada | Media (4.6) | 0.41% | — | Krylack ZIP Password RecoveryAI | 11/2/2026 | 17/6/2026 | ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file. | |
| Aplazada | Media (6.7) | 0.22% | — | MSN Password RecoveryAI | 11/2/2026 | 17/6/2026 | MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration… | |
| Aplazada | Media (4.6) | 0.30% | — | TOP Password Software Dialup Password RecoveryAI | 11/2/2026 | 17/6/2026 | Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields. | |
| Aplazada | Media (4.6) | 0.30% | — | TOP Password Firefox Password RecoveryAI | 11/2/2026 | 17/6/2026 | Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields. | |
| Aplazada | Media (4.6) | 0.30% | — | Gtalk Password FinderAI | 11/2/2026 | 17/6/2026 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.30% | — | Keepass Password SafeAI | 11/2/2026 | 17/6/2026 | KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Xpoda Turkiye Information Technology INC Password ModuleAI | 9/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026. | |
| Aplazada | Media (6.7) | 0.45% | — | Spotftp-ftp Password RecoverAI | 7/2/2026 | 17/6/2026 | SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash. | |
| Analizada | Alta (8.1) | 0.80% | — | Zohocorp Manageengine Pam360Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Password Manager PRO | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality. | |
| Aplazada | Media (6.5) | 0.15% | — | Jcaruso001 Flaming-password-resetAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jcaruso001 Flaming Password Reset flaming-password-reset allows Stored XSS.This issue affects Flaming Password Reset: from n/a through <= 1.0.3. | |
| Aplazada | Crítica (9.8) | 0.43% | — | FS Registration PasswordAI | 6/1/2026 | 30/9/2026 | The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.0.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change… |