Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

567 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.63%—Paloaltonetworks Pan-osAI12/2/202517/6/2026
An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system…
AnalizadaAlta (8.8)98%⚠ Explotación activa💥 ExploitPaloaltonetworks Pan-os12/2/202524/9/2026
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not…
AnalizadaAlta (7.7)79%💥 ExploitPaloaltonetworks Expedition11/1/202517/6/2026
An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
AnalizadaMedia (6.9)0.48%—Paloaltonetworks Expedition11/1/202517/6/2026
A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem.
AnalizadaMedia (6.9)13%—Paloaltonetworks Expedition11/1/202517/6/2026
An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem.
AnalizadaAlta (7)0.36%—Paloaltonetworks Expedition11/1/202517/6/2026
A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition…
AnalizadaCrítica (9.2)0.62%—Paloaltonetworks Expedition11/1/202517/6/2026
An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
AnalizadaAlta (8.7)29%⚠ Explotación activaPaloaltonetworks Pan-osPaloaltonetworks Prisma Access27/12/202417/6/2026
A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance…
AnalizadaAlta (7.5)0.56%—Lopalopa E-learning Management System9/12/202417/6/2026
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.
AnalizadaCrítica (9.8)0.92%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System9/12/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
ModificadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
ModificadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
ModificadaAlta (7.2)0.58%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
AnalizadaAlta (8.8)0.58%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.
ModificadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.