Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.33% | — | Lopalopa Music Management System | 16/9/2024 | 17/6/2026 | Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user. | |
| Analizada | Media (5.3) | 0.32% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect users impersonated by an attacker who is exploiting this vulnerability are disconnected from GlobalProtect. Upon… | |
| Analizada | Media (5.6) | 0.19% | — | Paloaltonetworks Cortex XDR Agent | 11/9/2024 | 17/6/2026 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and then to perform malicious activity. | |
| Aplazada | Media (6) | 0.22% | — | Paloaltonetworks Cortex XsoarAIPaloaltonetworks Cortex XsiamAIApache ActivemqAI | 11/9/2024 | 17/6/2026 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. | |
| Analizada | Media (6.7) | 0.24% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access to the CLI to to read arbitrary files on the firewall. | |
| Analizada | Media (6.9) | 0.41% | — | Paloaltonetworks Pan-osPaloaltonetworks GlobalprotectPaloaltonetworks Prisma Access | 11/9/2024 | 17/6/2026 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password and the configured disable or disconnect passcode. After the password or passcode is known, end users can uninstall, disable, or… | |
| Analizada | Alta (8.6) | 1.4% | — | Paloaltonetworks Pan-os | 11/9/2024 | 17/6/2026 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | |
| Analizada | Alta (8) | 0.24% | — | Lopalopa Music Management System | 28/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page. | |
| Analizada | Alta (7.2) | 0.38% | — | Lopalopa Responsive School Management System | 28/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page | |
| Analizada | Baja (3.5) | 0.20% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page. | |
| Analizada | Media (5.4) | 0.49% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/index.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter. | |
| Analizada | Alta (8.8) | 0.62% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre. | |
| Analizada | Media (6.1) | 0.52% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "artist" parameter fields. | |
| Analizada | Media (6.3) | 0.64% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/music/controller.php?page=test" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via the "page" parameter. | |
| Analizada | Media (6.1) | 0.52% | — | Lopalopa Music Management System | 26/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This vulnerability allows remote attackers to execute arbitrary code via "title" & "description" parameter fields. | |
| Analizada | Alta (8.8) | 0.57% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page. | |
| Analizada | Alta (8.8) | 0.53% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter. | |
| Analizada | Crítica (9.8) | 0.38% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter. | |
| Analizada | Crítica (9.8) | 0.47% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter. | |
| Analizada | Crítica (9.8) | 0.67% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter. | |
| Analizada | Alta (8.8) | 0.80% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Alta (8.8) | 0.79% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Alta (8.8) | 0.79% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Crítica (9.8) | 0.73% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. |