Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.66%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
AnalizadaAlta (8.8)0.50%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
AnalizadaMedia (6.5)0.75%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
ModificadaMedia (5.4)0.83%—Koa-remove-trailing-slashes Project Koa-remove-trailing-slashes17/5/202117/6/2026
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative…
ModificadaCrítica (9.8)2.5%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and T710s…
ModificadaAlta (7.5)2.4%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
Incorrect access control in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to leak system information (that can be used for a jailbreak) via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300,…
ModificadaCrítica (9.8)2.1%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s, T610, T710, and…
ModificadaCrítica (9.8)3.6%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
A stack buffer overflow in webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,…
ModificadaAlta (7.5)1.9%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
Insecure permissions in emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allow a remote attacker to overwrite admin credentials via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d,…
ModificadaAlta (7.5)2.3%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
webs in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to cause a denial of service (Segmentation fault) to the webserver via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c,…
ModificadaMedia (6.1)1.3%—Ruckuswireless Unleashed Firmware28/7/202017/6/2026
An XSS issue in emfd in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to execute JavaScript code via an unauthenticated crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R710, R720, R750, T300, T301n, T301s, T310c, T310d, T310n, T310s,…
ModificadaCrítica (9.8)3.3%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.
ModificadaCrítica (9.8)24%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.
ModificadaMedia (5.3)2.0%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
ModificadaAlta (7.5)1.8%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware23/1/202017/6/2026
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
ModificadaCrítica (9.8)5.0%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.
ModificadaCrítica (9.8)3.3%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
ModificadaCrítica (9.8)4.1%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
A stack-based buffer overflow in zap_parse_args in zap.c in zap in Ruckus Unleashed through 200.7.10.102.64 allows remote code execution via an unauthenticated HTTP request.
ModificadaCrítica (9.8)1.8%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a symlink with /tmp and web/user/wps_tool_cache.
ModificadaCrítica (9.8)3.6%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote code execution via a POST request that uses tools/_rcmdstat.jsp to write to a specified filename.
ModificadaAlta (7.2)2.2%—Ruckuswireless UnleashedRuckuswireless Zonedirector 1200 Firmware22/1/202017/6/2026
Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jailbreak the CLI via enable->debug->script->exec with ../../../bin/sh as the parameter.
ModificadaCrítica (9.8)2.3%—Archivesunleashed Graphpass15/7/201917/6/2026
borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.