Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.66% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. | |
| Analizada | Alta (8.8) | 0.50% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. | |
| Analizada | Media (6.5) | 0.75% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data. | |
| Modificada | Media (5.4) | 0.83% | — | Koa-remove-trailing-slashes Project Koa-remove-trailing-slashes | 17/5/2021 | 17/6/2026 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative… | |
| Modificada | Crítica (9.8) | 2.5% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s… | |
| Modificada | Alta (7.5) | 2.4% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | Incorrect access control in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to leak system information (that can be used for a jailbreak) via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300,… | |
| Modificada | Crítica (9.8) | 2.1% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and… | |
| Modificada | Crítica (9.8) | 3.6% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,… | |
| Modificada | Alta (7.5) | 1.9% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d,… | |
| Modificada | Alta (7.5) | 2.3% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c,… | |
| Modificada | Media (6.1) | 1.3% | — | Ruckuswireless Unleashed Firmware | 28/7/2020 | 17/6/2026 | An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,… | |
| Modificada | Crítica (9.8) | 3.3% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 23/1/2020 | 17/6/2026 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute. | |
| Modificada | Crítica (9.8) | 24% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 23/1/2020 | 17/6/2026 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute. | |
| Modificada | Media (5.3) | 2.0% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 23/1/2020 | 17/6/2026 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests. | |
| Modificada | Alta (7.5) | 1.8% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 23/1/2020 | 17/6/2026 | SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI. | |
| Modificada | Crítica (9.8) | 5.0% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute. | |
| Modificada | Crítica (9.8) | 3.3% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute. | |
| Modificada | Crítica (9.8) | 4.1% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request. | |
| Modificada | Crítica (9.8) | 1.8% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename. | |
| Modificada | Alta (7.2) | 2.2% | — | Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware | 22/1/2020 | 17/6/2026 | Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archivesunleashed Graphpass | 15/7/2019 | 17/6/2026 | borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable. |