Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.80% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Alta (8.8) | 0.79% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Alta (8.8) | 0.79% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Crítica (9.8) | 0.73% | — | Lopalopa Music Management System | 21/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Aplazada | Media (6.1) | 0.49% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (4.3) | 0.59% | — | Opal MembershipAI | 12/8/2024 | 17/6/2026 | The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view… | |
| Analizada | Alta (8.8) | 0.33% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php. | |
| Analizada | Alta (7.6) | 1.1% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter. | |
| Analizada | Crítica (9.8) | 1.0% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (5.3) | 0.41% | — | Lopalopa Responsive School Management System | 8/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (4.8) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field. | |
| Analizada | Crítica (9.8) | 0.59% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | |
| Analizada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.46% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | |
| Modificada | Media (6.1) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter. | |
| Modificada | Media (5.3) | 0.48% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details. | |
| Analizada | Media (5.3) | 0.55% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details. | |
| Analizada | Media (5.3) | 0.47% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details. | |
| Modificada | Media (5.3) | 0.51% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details. | |
| Analizada | Media (6.5) | 0.39% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration. | |
| Modificada | Media (6.5) | 0.45% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration. | |
| Analizada | Media (5.3) | 0.64% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details. | |
| Analizada | Media (5.3) | 0.54% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry. | |
| Analizada | Media (5.3) | 0.43% | — | Lopalopa Responsive School Management System | 7/8/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry. |