Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Simple E-learning System Project Simple E-learning System | 7/10/2022 | 17/6/2026 | An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode. | |
| Modificada | Media (6.1) | 3.0% | 💥 Exploit | Creativeitem Academy Learning Management System | 26/9/2022 | 9/7/2026 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |
| Modificada | Alta (7.5) | 0.82% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.54% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affects unknown code of the file /claire_blake. The manipulation of the argument Bio leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 0.67% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /claire_blake. The manipulation of the argument phoneNumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.75% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument searchPost leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been classified as critical. Affected is an unknown function of the file comment_frame.php. The manipulation of the argument post_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.58% | — | Simple E-learning System Project Simple E-learning System | 5/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerability is an unknown functionality of the file classroom.php. The manipulation of the argument post_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.78% | — | Simple E-learning System Project Simple E-learning System | 20/7/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x74666264 WHERE 5610=5610 AND (SELECT 7504 FROM(SELECT… | |
| Modificada | Alta (8.8) | 0.78% | — | Simple E-learning System Project Simple E-learning System | 20/7/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System 1.0. It has been rated as critical. This issue affects some unknown processing of the file classRoom.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x6770715a WHERE 8795=8795 AND (SELECT 8342 FROM(SELECT… | |
| Modificada | Media (5.4) | 0.56% | — | Simple E-learning System Project Simple E-learning System | 14/7/2022 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>alert(document.cookie)</script> leads to cross site scripting. The… | |
| Modificada | Crítica (9.3) | 1.3% | — | Deep Learning Studio Project Deep Learning Studio | 11/7/2022 | 17/6/2026 | The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.5) | 1.1% | — | Nvidia Federated Learning Application Runtime Environment | 17/3/2022 | 17/6/2026 | NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable. | |
| Modificada | Media (4.8) | 0.60% | — | Cluevo Learning Management System | 7/2/2022 | 17/6/2026 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.60% | — | Nd-learning Project Nd-learning | 1/2/2022 | 17/6/2026 | The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.5) | 12% | — | Apache Xerces-jOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Deposits AND Lines OF Credit Servicing+25 | 24/1/2022 | 25/8/2026 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version… | |
| Modificada | Crítica (9.8) | 1.3% | — | Oretnom23 Online Learning System | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter. | |
| Modificada | Crítica (9.8) | 10.0% | 💥 Exploit | Oretnom23 Online Learning System | 15/11/2021 | 17/6/2026 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution. | |
| Modificada | Media (4.3) | 0.84% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters. | |
| Modificada | Media (5.4) | 0.59% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack. | |
| Modificada | Alta (8.8) | 1.1% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions. | |
| Modificada | Alta (8.8) | 1.1% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions. | |
| Modificada | Crítica (9.8) | 1.9% | — | Learning Management System Project Learning Management System | 30/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Learning Management System Project Learning Management System | 23/7/2021 | 17/6/2026 | SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… |