Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.80%—Lopalopa Music Management System21/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.
AnalizadaAlta (8.8)0.79%—Lopalopa Music Management System21/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.
ModificadaAlta (8.8)0.79%—Lopalopa Music Management System21/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.
AnalizadaCrítica (9.8)0.73%—Lopalopa Music Management System21/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
AplazadaMedia (6.1)0.49%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via checkout form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will…
AplazadaMedia (4.3)0.59%—Opal MembershipAI12/8/202417/6/2026
The Opal Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.4 via the private notes functionality on payments which utilizes WordPress comments. This makes it possible for authenticated attackers, with subscriber-level access and above, to view…
AnalizadaAlta (8.8)0.33%—Lopalopa Live Membership System12/8/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php.
AnalizadaAlta (7.6)1.1%—Lopalopa Live Membership System12/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.
AnalizadaCrítica (9.8)1.0%—Lopalopa Live Membership System12/8/202417/6/2026
A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
AnalizadaCrítica (9.8)1.2%—Lopalopa Live Membership System12/8/202417/6/2026
An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.
AnalizadaMedia (5.3)0.41%—Lopalopa Responsive School Management System8/8/202417/6/2026
A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
AnalizadaMedia (4.8)0.51%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field.
AnalizadaCrítica (9.8)0.59%—Lopalopa Responsive School Management System7/8/202417/6/2026
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
AnalizadaMedia (6.1)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
ModificadaMedia (6.1)0.46%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
ModificadaMedia (6.1)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter.
ModificadaMedia (5.3)0.48%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.
AnalizadaMedia (5.3)0.55%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.
AnalizadaMedia (5.3)0.47%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.
ModificadaMedia (5.3)0.51%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.
AnalizadaMedia (6.5)0.39%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration.
ModificadaMedia (6.5)0.45%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.
AnalizadaMedia (5.3)0.64%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.
AnalizadaMedia (5.3)0.54%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.
AnalizadaMedia (5.3)0.43%—Lopalopa Responsive School Management System7/8/202417/6/2026
An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry.
Orbitaley — Vulnerabilidades