Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

335 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter.
ModificadaMedia (6)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.
ModificadaAlta (8.5)1.5%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions.
ModificadaAlta (9.3)1.9%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html.
ModificadaMedia (4.3)1.4%—Oracle Ilearning17/7/201316/6/2026
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.
ModificadaMedia (5)1.5%—Efrontlearning Efront24/1/201316/6/2026
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
ModificadaBaja (3.5)0.97%—Efrontlearning Efront13/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message.
ModificadaMedia (6)2.1%—Efrontlearning Efront13/8/201216/6/2026
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message.
ModificadaAlta (7.5)2.5%💥 ExploitHypermethod Elearning Server21/5/201216/6/2026
PHP remote file inclusion vulnerability in admin/setup.inc.php in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
ModificadaAlta (7.5)1.1%💥 ExploitHypermethod Elearning Server21/5/201216/6/2026
SQL injection vulnerability in news.php4 in Hypermethod eLearning Server 4G allows remote attackers to execute arbitrary SQL commands via the nid parameter.
ModificadaMedia (4.3)1.5%💥 ExploitEfrontlearning Efront Community ++12/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
ModificadaAlta (7.5)1.2%💥 ExploitEfrontlearning Efront12/5/201016/6/2026
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.
ModificadaMedia (6.8)5.0%💥 ExploitEfrontlearning Efront19/3/201016/6/2026
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langname parameter.
ModificadaAlta (7.5)1.3%—Preprojects PRE E-learning Portal10/3/201016/6/2026
SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.
ModificadaMedia (6.8)1.9%💥 ExploitEfrontlearning Efront11/10/200916/6/2026
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the…
ModificadaMedia (6.8)4.7%💥 ExploitEfrontlearning Efront21/8/200916/6/2026
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.
ModificadaMedia (5)1.3%—Preprojects PRE E-learning Portal4/2/200916/6/2026
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
ModificadaAlta (7.5)1.0%💥 ExploitElearningforce Flash Magazine Deluxe30/1/200916/6/2026
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.
ModificadaAlta (7.5)3.3%💥 ExploitDokeos E-learning System30/7/200816/6/2026
Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter.
ModificadaMedia (6.8)27%💥 ExploitElearningforce Online Flashquiz4/4/200816/6/2026
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.
ModificadaAlta (7.5)2.2%—Dokeos Open Source Learning AND Knowledge Management Tool10/3/200816/6/2026
Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)1.2%—Dokeos Open Source Learning AND Knowledge Management Tool10/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)4.0%💥 ExploitDokeos E-learning System21/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to…
ModificadaMedia (4.3)1.8%💥 ExploitDokeos Open Source Learning AND Knowledge ManagementDokeos Open Source Learning AND Knowledge Management Tool28/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php.
ModificadaAlta (7.5)1.4%—Trivantis Coursemill Enterprise Learning Management System15/12/200716/6/2026
SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information.
Orbitaley — Vulnerabilidades