Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.5% | — | Oracle Ilearning | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human… | |
| Modificada | Alta (7.5) | 1.1% | — | Elearningcoinerc Project Elearningcoinerc | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ELearningCoinERC, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.4) | 1.5% | — | Learning AND Examination Management System Script Project Learning AND Examination Management System Script | 23/2/2018 | 17/6/2026 | Cross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message. | |
| Modificada | Media (6.5) | 1.2% | — | Efrontlearning Efront | 5/2/2018 | 17/6/2026 | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Advance Online Learning Management Script Project Advance Online Learning Management Script | 13/12/2017 | 17/6/2026 | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. | |
| Modificada | Crítica (9.8) | 1.7% | — | Intel Deep Learning Training Tool | 21/11/2017 | 17/6/2026 | A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to remotely execute code as a local user. | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Ilearning | 8/8/2017 | 17/6/2026 | Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction… | |
| Modificada | Media (6.5) | 1.2% | — | Efrontlearning Efront | 25/7/2017 | 17/6/2026 | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL. | |
| Modificada | Media (6.5) | 1.1% | — | Efrontlearning Efront | 25/7/2017 | 17/6/2026 | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Ilearning | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Administration. | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Ilearning | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Login. | |
| Modificada | Media (4.3) | 1.2% | — | Oracle Ilearning | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect confidentiality via unknown vectors related to Learner Pages. | |
| Modificada | Media (5.4) | 0.27% | — | Ilearnwith Kids Preschool Learning Games | 9/9/2014 | 17/6/2026 | The Kids Preschool Learning Games (aka air.com.tribalnova.ilearnwith.ipad.App3En) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Efrontlearning Efront | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php. | |
| Modificada | Media (4.3) | 1.0% | — | Oracle Ilearning | 16/4/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Pages. | |
| Modificada | Media (4.3) | 2.4% | — | Oracle Ilearning | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in Oracle iLearning 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages. | |
| Modificada | Baja (3.5) | 2.6% | 💥 Exploit | Efrontlearning Efront | 21/12/2013 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field. | |
| Modificada | Media (4.3) | 0.98% | — | Oracle Ilearning | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Administration. | |
| Modificada | Media (6.8) | 1.2% | — | Oracle Ilearning | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Learner Administration. | |
| Modificada | Media (6.8) | 0.70% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML… | |
| Modificada | Media (6.8) | 0.62% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies. | |
| Modificada | Media (4.3) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.6 allow remote attackers to inject arbitrary web script or HTML via crafted input. | |
| Modificada | Media (4.3) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages. |