Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter. | |
| Modificada | Media (6) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter. | |
| Modificada | Alta (8.5) | 1.5% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions. | |
| Modificada | Alta (9.3) | 1.9% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html. | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Ilearning | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages. | |
| Modificada | Media (5) | 1.5% | — | Efrontlearning Efront | 24/1/2013 | 16/6/2026 | eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message. | |
| Modificada | Baja (3.5) | 0.97% | — | Efrontlearning Efront | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message. | |
| Modificada | Media (6) | 2.1% | — | Efrontlearning Efront | 13/8/2012 | 16/6/2026 | Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Hypermethod Elearning Server | 21/5/2012 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Hypermethod Elearning Server | 21/5/2012 | 16/6/2026 | SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Efrontlearning Efront Community ++ | 12/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Efrontlearning Efront | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. | |
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Efrontlearning Efront | 19/3/2010 | 16/6/2026 | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Preprojects PRE E-learning Portal | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Efrontlearning Efront | 11/10/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the… | |
| Modificada | Media (6.8) | 4.7% | 💥 Exploit | Efrontlearning Efront | 21/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/. | |
| Modificada | Media (5) | 1.3% | — | Preprojects PRE E-learning Portal | 4/2/2009 | 16/6/2026 | PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Elearningforce Flash Magazine Deluxe | 30/1/2009 | 16/6/2026 | SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Dokeos E-learning System | 30/7/2008 | 16/6/2026 | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter. | |
| Modificada | Media (6.8) | 27% | 💥 Exploit | Elearningforce Online Flashquiz | 4/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Dokeos E-learning System | 21/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Dokeos Open Source Learning AND Knowledge ManagementDokeos Open Source Learning AND Knowledge Management Tool | 28/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Trivantis Coursemill Enterprise Learning Management System | 15/12/2007 | 16/6/2026 | SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information. |