Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.16%—Intel Hardware-aware-automated-machine-learning11/8/20262/10/2026
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AplazadaBaja (2.1)0.32%—Sourcecodester Simple E-learning SystemAI23/3/202617/6/2026
A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.32%—Sourcecodester Simple E-learning SystemAI23/3/202617/6/2026
A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection. It is possible to initiate the attack…
AplazadaBaja (2.1)0.47%—Jcharis Machine-learning-web-appsAIPocoo Jinja2AI11/3/202617/6/2026
A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such…
AplazadaAlta (8.8)0.41%—E-learning PHP ScriptAI30/1/202617/6/2026
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.
AnalizadaBaja (2.1)0.39%—Janobe E-learning System19/1/202617/6/2026
A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The…
AnalizadaMedia (5.5)0.48%—Jkev Responsive E-learning System18/9/202517/6/2026
A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /admin/add_teacher.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AplazadaBaja (2.9)0.43%—Youth-is-as-pale-as-poetry E-learningAI18/9/202530/9/2026
A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token Handler. The manipulation leads to insufficiently random values. The attack can…
AnalizadaMedia (6.9)0.49%—Jkev Responsive E-learning System27/5/202517/6/2026
A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_file.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (5.1)0.40%—Janobe E-learning System23/2/202517/6/2026
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
AnalizadaMedia (5.3)0.48%—Janobe E-learning System23/2/202517/6/2026
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.
AnalizadaCrítica (9.8)0.72%—Jkev Responsive E-learning System5/2/202517/6/2026
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.
AnalizadaAlta (7.5)0.56%—Lopalopa E-learning Management System9/12/202417/6/2026
A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.
AnalizadaCrítica (9.8)0.51%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,
AnalizadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System9/12/202417/6/2026
A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.
AnalizadaCrítica (9.8)0.92%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System9/12/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
ModificadaAlta (7.2)0.49%—Lopalopa E-learning Management System9/12/202417/6/2026
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
Orbitaley — Vulnerabilidades