Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.77%—BlackboardAI21/11/20245/7/2026
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.
ModificadaMedia (6.5)1.4%💥 PoCBlackboard Learn5/9/202217/6/2026
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certain webapps/bbcms/execute/ URL. Note: The vendor disputes this stating this cannot be reproduced.
ModificadaMedia (5.4)0.62%💥 PoCBlackboard Learn20/7/202117/6/2026
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.
ModificadaMedia (5.4)0.56%—Blackboard Learn20/7/202117/6/2026
Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.
ModificadaMedia (6.1)0.69%—Blackboard Collaborate Ultra2/3/202117/6/2026
Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which leads to stealing cookies from users who join the class. NOTE: Third-parties dispute the validity of this entry as a possible false positive during research
ModificadaMedia (5.4)0.62%💥 PoCBlackboard Learn25/2/202017/6/2026
Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget in the People Tool profile editor.
ModificadaMedia (6.1)1.2%💥 PoCBlackboard Learn18/11/201917/6/2026
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
ModificadaMedia (6.1)1.4%—Blackboard Learn30/4/201817/6/2026
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
ModificadaMedia (4.3)1.8%—Blackboard Vista/ce22/2/201417/6/2026
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)0.88%—Blackboard Transact Suite7/9/201016/6/2026
The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which allows local users to obtain sensitive information by reading a file.
ModificadaMedia (4.6)0.30%—Blackboard Transact Suite7/9/201016/6/2026
BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml field value, which allows local users to discover the database password via a modified connection.xml file that contains…
ModificadaMedia (4.3)0.53%—Blackboard Academic Suite31/7/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.
ModificadaMedia (6.8)1.3%—Blackboard Academic Suite18/4/200816/6/2026
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attackers to access accounts via a modified client that skips the javascript/md5.js hash calculation, and instead sends an arbitrary MD5 string.
ModificadaMedia (4.3)1.9%💥 ExploitBlackboard Academic Suite15/4/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0 versions, allow remote attackers to inject arbitrary web script or HTML via (1) the searchText parameter in a Course action to webapps/blackboard/execute/viewCatalog or (2) the…
ModificadaAlta (7.5)1.3%—Husrev Blackboard13/2/200816/6/2026
SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
ModificadaMedia (4.3)1.1%—Blackboard Learning AND Community Post Systems5/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing…
ModificadaMedia (4.3)2.0%💥 ExploitBlackboardBlackboard Learning AND Community Portal SuiteBlackboard Vista23/8/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML…
ModificadaMedia (6)1.1%—Blackboard Academic Suite28/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web script by bypassing client-side validation through disabling JavaScript when submitting an essay response, which has no server-side validation before being viewed via "View…
ModificadaMedia (4.3)0.36%—BlackboardBlackboard Academic Suite1/2/200616/6/2026
Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their…
ModificadaMedia (5)1.2%—Blackboard Academic Suite19/12/200516/6/2026
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether this information is sensitive or not, so this might not be an…
ModificadaAlta (7.5)1.5%—Blackboard Academic Suite19/12/200516/6/2026
The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter.
ModificadaMedia (4.3)0.95%—Blackboard Academic Suite19/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to announcement.pl, which is reflected in the resulting page.
ModificadaAlta (10)2.7%—Blackboard Academic Suite19/12/200516/6/2026
announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin".
ModificadaMedia (6.1)2.1%💥 ExploitBlackboard Academic Suite13/12/200516/6/2026
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a…
ModificadaAlta (7.5)1.7%—Blackboard Internet Newsboard System31/12/200416/6/2026
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
Orbitaley — Vulnerabilidades