Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.25% | — | Paloaltonetworks Pan-os | 14/8/2024 | 17/6/2026 | An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of external systems. A read-only administrator who has access to the config log, can read secrets, passwords, and tokens to external systems. | |
| Analizada | Media (5.2) | 0.21% | — | Paloaltonetworks Globalprotect | 14/8/2024 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. | |
| Analizada | Alta (7) | 1.2% | — | Paloaltonetworks Cortex Xsoar Commonscripts | 14/8/2024 | 17/6/2026 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | |
| Analizada | Alta (8.8) | 0.33% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php. | |
| Analizada | Alta (7.6) | 1.1% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter. | |
| Analizada | Crítica (9.8) | 1.0% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (5.3) | 0.41% | — | Lopalopa Responsive School Management System | 8/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (4.8) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field. | |
| Analizada | Crítica (9.8) | 0.59% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.46% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter. | |
| Modificada | Media (5.3) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details. | |
| Analizada | Media (5.3) | 0.55% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details. | |
| Analizada | Media (5.3) | 0.47% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details. | |
| Modificada | Media (5.3) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details. | |
| Analizada | Media (6.5) | 0.39% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration. | |
| Modificada | Media (6.5) | 0.45% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration. | |
| Analizada | Media (5.3) | 0.64% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details. | |
| Analizada | Media (5.3) | 0.54% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry. | |
| Analizada | Media (5.3) | 0.43% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry. | |
| Modificada | Media (5.3) | 0.54% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard. | |
| Analizada | Media (6.8) | 0.23% | — | Paloaltonetworks Pan-os | 10/7/2024 | 17/6/2026 | An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to elevate privileges. | |
| Aplazada | Media (6.8) | 0.13% | — | Paloaltonetworks Cortex XDR AgentAI | 10/7/2024 | 17/6/2026 | An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked. |