Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.63% | — | Paloaltonetworks Pan-osAI | 12/2/2025 | 17/6/2026 | An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system… | |
| Analizada | Alta (8.8) | 98% | ⚠ Explotación activa💥 Exploit | Paloaltonetworks Pan-os | 12/2/2025 | 24/9/2026 | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not… | |
| Analizada | Alta (7.7) | 79% | 💥 Exploit | Paloaltonetworks Expedition | 11/1/2025 | 17/6/2026 | An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software. | |
| Analizada | Media (6.9) | 0.48% | — | Paloaltonetworks Expedition | 11/1/2025 | 17/6/2026 | A wildcard expansion vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to enumerate files on the host filesystem. | |
| Analizada | Media (6.9) | 13% | — | Paloaltonetworks Expedition | 11/1/2025 | 17/6/2026 | An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. | |
| Analizada | Alta (7) | 0.36% | — | Paloaltonetworks Expedition | 11/1/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that allows phishing attacks and could lead to Expedition… | |
| Analizada | Crítica (9.2) | 0.62% | — | Paloaltonetworks Expedition | 11/1/2025 | 17/6/2026 | An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system. | |
| Analizada | Alta (8.7) | 29% | ⚠ Explotación activa | Paloaltonetworks Pan-osPaloaltonetworks Prisma Access | 27/12/2024 | 17/6/2026 | A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance… | |
| Analizada | Alta (7.5) | 0.56% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads. | |
| Analizada | Crítica (9.8) | 0.51% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. | |
| Analizada | Crítica (9.8) | 0.51% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. | |
| Analizada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, | |
| Analizada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters. | |
| Analizada | Crítica (9.8) | 0.92% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. | |
| Modificada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php. | |
| Modificada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php. | |
| Modificada | Alta (7.2) | 0.58% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters. | |
| Analizada | Alta (8.8) | 0.58% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter. | |
| Modificada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters. |