Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

9810 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.5)0.32%—HPE Networking Instant ONAI29/9/202630/9/2026
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected…
Pendiente de análisisMedia (6.5)0.21%—HPE Instant ON APSAI29/9/202630/9/2026
An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send…
Pendiente de análisisMedia (6.6)0.42%—HPE Networking Instant ON APSAI29/9/20261/10/2026
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the…
Pendiente de análisisAlta (7.2)0.55%—HPE Networking Instant ON Access PointAI29/9/20266/10/2026
A vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to conduct a server-side request forgery (SSRF) attack. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating…
Pendiente de análisisAlta (7.2)0.98%—HPE Networking Instant ONAI29/9/20261/10/2026
Command injection vulnerabilities exist in the affected interface of HPE Networking Instant ON that could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying…
Pendiente de análisisAlta (8.1)0.36%—HPE Networking Instant ONAI29/9/20261/10/2026
An authentication bypass vulnerability in the API endpoint of HPE Networking Instant ON could allow an unauthenticated remote attacker to bypass network access controls if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to obtain unauthorized access to…
Pendiente de análisisCrítica (9.6)0.32%—HPE Instant ONAI29/9/20261/10/2026
A vulnerability has been identified in a management protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could result in a complete bypass of security restrictions, potentially leading to remote code…
Pendiente de análisisCrítica (9.6)1.0%—HPE Instant ONAI29/9/20261/10/2026
A command injection vulnerability exists in CLI of the affected HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to perform command injection by sending specially crafted packets. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on…
Pendiente de análisisCrítica (9.6)0.31%—HPE Networking Instant ON APSAI29/9/20261/10/2026
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
Pendiente de análisisCrítica (9.8)0.54%—HPE Networking Instant ONAI29/9/20261/10/2026
Uncontrolled Format string vulnerabilities exist in the affected interface of HPE Networking Instant ON APs that could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation could result in a Denial-of-service or potential remote code execution.
Pendiente de análisisCrítica (9.8)0.56%—HPE Networking Instant ONAI29/9/202630/9/2026
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
Pendiente de análisisBaja (3.5)0.34%—Thephpleague FlysystemAI29/9/202630/9/2026
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by Filesystem across adapters calls preg_match with the u modifier and treats both false and 0 as falsy. A path containing malformed UTF-8 causes PCRE to return…
Pendiente de análisisMedia (4.3)0.17%—HPE OneviewAI29/9/202629/9/2026
A vulnerability in HPE OneView can be remotely exploited to cause a URL redirect.
Pendiente de análisisAlta (8.2)0.18%—HPE OneviewAI29/9/202629/9/2026
A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.
Pendiente de análisisAlta (8.2)0.24%—HPE OneviewAI29/9/202629/9/2026
A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.
AplazadaMedia (5.5)0.25%—Mathurvishal Cloudclassroom PHP ProjectAI28/9/202628/9/2026
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit…
AplazadaMedia (5.5)0.25%—Mathurvishal Cloudclassroom PHP ProjectAI28/9/20261/10/2026
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available…
AplazadaBaja (2)0.15%—Devaslanphp Project ManagementAI28/9/20261/10/2026
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate…
AplazadaBaja (2.1)0.19%—Devaslanphp Project ManagementAI28/9/202628/9/2026
A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may…
AplazadaBaja (2.1)0.19%—Devaslanphp Project-managementAI28/9/202628/9/2026
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The…
AplazadaBaja (2.1)0.30%—Mathurvishal Cloudclassroom PHP ProjectAI28/9/20261/10/2026
A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly…
AplazadaBaja (2.1)0.26%—Mathurvishal Cloudclassroom PHP ProjectAI27/9/202628/9/2026
A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack…
AplazadaBaja (2.1)0.28%—Vishalmathur Cloudclassroom-php-projectAI27/9/202630/9/2026
A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The…
AplazadaMedia (5.5)0.25%—Mathurvishal Cloudclassroom PHP ProjectAI27/9/202628/9/2026
A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been…
AplazadaMedia (5.5)0.25%—Mathurvishal Cloudclassroom PHP ProjectAI27/9/202628/9/2026
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product…