Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.63%—Teampasswordmanager Team Password ManagerAI1/9/202623/9/2026
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
AnalizadaMedia (4.6)0.31%—Teampasswordmanager Team Password Manager4/3/202517/6/2026
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.
ModificadaAlta (7.5)0.79%—Teampasswordmanager Team Password Manager19/11/202117/6/2026
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
ModificadaAlta (8.8)0.43%—Teampasswordmanager Team Password Manager19/11/202117/6/2026
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
ModificadaMedia (5.4)0.54%—Teampasswordmanager Team Password Manager16/3/202017/6/2026
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
ModificadaMedia (6.1)0.81%—Keynto Team Password Manager9/7/201917/6/2026
KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.