Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)0.50%—Wpopal Opal WOO Custom Product VariationAI23/5/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-product-variation allows Path Traversal.This issue affects Opal Woo Custom Product Variation: from n/a through <= 1.2.0.
AnalizadaAlta (8.8)0.48%—Lopalopa Online Service Management Portal5/5/202517/6/2026
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.
AnalizadaAlta (8.8)0.48%—Lopalopa Online Service Management Portal5/5/202517/6/2026
kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.
AnalizadaMedia (5.3)0.40%—Lopalopa Online Service Management Portal5/5/202517/6/2026
A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.
AplazadaAlta (8.6)0.40%—Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+1926/4/202517/6/2026
A vulnerability classified as critical has been found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl,…
AplazadaMedia (5.1)0.22%—Gl-inet Gl-a1300 Slate PlusAIGl-inet Gl-ar300m16 ShadowAIGl-inet Gl-ar300m ShadowAIGl-inet Gl-ar750 CretaAI+1926/4/202517/6/2026
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000…
AplazadaMedia (6.9)0.36%—Gl-inet GL A1300 Slate PlusAIGl-inet GL Ar300m16 ShadowAIGl-inet GL Ar300m ShadowAIGl-inet GL Ar750 CretaAI+1926/4/202517/6/2026
A vulnerability was found in GL.iNet GL-A1300 Slate Plus, GL-AR300M16 Shadow, GL-AR300M Shadow, GL-AR750 Creta, GL-AR750S-EXT Slate, GL-AX1800 Flint, GL-AXT1800 Slate AX, GL-B1300 Convexa-B, GL-B3000 Marble, GL-BE3600 Slate 7, GL-E750, GL-E750V2 Mudi, GL-MT300N-V2 Mango, GL-MT1300 Beryl, GL-MT2500 Brume 2, GL-MT3000…
AplazadaAlta (7.1)0.29%—Dhanendran Rajagopal Term Taxonomy ConverterAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dhanendran Rajagopal Term Taxonomy Converter term-taxonomy-converter allows Reflected XSS.This issue affects Term Taxonomy Converter: from n/a through <= 1.2.
AplazadaMedia (6.5)0.36%—Wpopal Opal PortfolioAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpopal Opal Portfolio opal-portfolios allows Stored XSS.This issue affects Opal Portfolio: from n/a through <= 1.0.4.
AplazadaAlta (7.7)0.29%—Obiba OpalAI11/3/202517/6/2026
Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request forgery (CSRF) were insufficient application-wide. The referrer header is checked, and if it is invalid, the server returns 403. However, the referrer header can be…
AplazadaAlta (7.3)0.58%—Obiba OpalAI11/3/202517/6/2026
Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying any parent directory to a folder in the /temp/ directory, all files in that parent directory are copied, including files which the user should not have access to. All users of the application are…
ModificadaAlta (8.8)0.19%—Venugopal Comment Date AND Gravatar Remover11/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Site Request Forgery.This issue affects Comment Date and Gravatar remover: from n/a through <= 1.0.
AplazadaAlta (7.1)0.15%—Venugopal Show Notice OR Message ON Admin AreaAI7/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Show notice or message on admin area show-notice-or-message-on-admin-area allows Stored XSS.This issue affects Show notice or message on admin area: from n/a through <= 2.0.
AplazadaAlta (7.1)0.36%—Franciscopalacios Easy FilteringAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in franciscopalacios Easy Filtering easy-filtering allows Reflected XSS.This issue affects Easy Filtering: from n/a through <= 2.5.0.
AnalizadaAlta (7.5)0.56%—Lopalopa E-learning Management System9/12/202417/6/2026
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.
AnalizadaCrítica (9.8)0.92%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.