Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

68 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)7.4%💥 ExploitIcewhale CasaosIcewhale Casaos-gateway17/7/202317/6/2026
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should…
ModificadaCrítica (9.8)1.5%—Rakuten Casa13/6/202217/6/2026
Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.
ModificadaAlta (7.2)2.6%—Rakuten Casa13/6/202217/6/2026
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN side, and is also connected to the…
ModificadaAlta (7.5)1.5%—Rakuten Casa13/6/202217/6/2026
Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.
ModificadaCrítica (9.8)5.5%—Icewhale Casaos10/3/202217/6/2026
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
ModificadaMedia (6.1)0.66%—Casap Automated Enrollment System Project Casap Automated Enrollment System8/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in…
ModificadaMedia (6.1)0.84%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/20219/7/2026
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
ModificadaCrítica (9.8)1.5%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.
ModificadaCrítica (9.8)1.5%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.
ModificadaMedia (6.1)0.87%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.
ModificadaCrítica (9.8)1.5%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
ModificadaCrítica (9.8)1.7%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
ModificadaMedia (6.1)0.87%—Casap Automated Enrollment System Project Casap Automated Enrollment System22/7/202117/6/2026
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.
ModificadaMedia (5.4)0.61%—Casap Automated Enrollment System Project Casap Automated Enrollment System15/4/202117/6/2026
CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.
ModificadaCrítica (9.8)2.2%—Casap Automated Enrollment System Project Casap Automated Enrollment System15/2/202117/6/2026
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
ModificadaMedia (5.4)2.8%💥 ExploitCasap Automated Enrollment System Project Casap Automated Enrollment System9/2/20219/7/2026
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.
ModificadaMedia (6.5)1.7%💥 ExploitMicasaverde Veralite Firmware28/1/202016/6/2026
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.
ModificadaCrítica (9.8)6.3%💥 ExploitMicasaverde Veralite Firmware28/1/202016/6/2026
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
ModificadaAlta (8.8)12%💥 ExploitMicasaverde Veralite Firmware28/1/202016/6/2026
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to…
ModificadaAlta (8.1)3.7%💥 ExploitMicasaverde Veralite Firmware28/1/202016/6/2026
MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.
ModificadaMedia (6.5)6.6%💥 ExploitMicasaverde Veralite Firmware28/1/202016/6/2026
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.
ModificadaAlta (7.5)1.4%—Americasarmy Proving Grounds10/7/201917/6/2026
An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, giving the possibility of DoS amplification, even being able to be used in DDoS attacks.
ModificadaAlta (10)4.0%—Google Picasa17/11/201517/6/2026
Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow.
ModificadaAlta (10)4.0%—Google Picasa9/11/201517/6/2026
Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow.
ModificadaMedia (4.3)1.6%—WP Picasa Image Project WP Picasa Image2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.
Orbitaley — Vulnerabilidades