Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Blackboard Learning AND Community Post Systems | 5/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing… | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Dokeos Open Source Learning AND Knowledge Management Tool | 30/5/2007 | 16/6/2026 | SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Angel Learning Learning Management Suite | 3/3/2007 | 16/6/2026 | SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Learning EssentialsMicrosoft OfficeMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 13/2/2007 | 16/6/2026 | The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which… | |
| Modificada | Media (5.1) | 10% | 💥 Exploit | ClarolineDokeos Open Source Learning AND Knowledge Management Tool | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Interact Learning Community Environment Interact | 30/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | BlackboardBlackboard Learning AND Community Portal SuiteBlackboard Vista | 23/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML… | |
| Modificada | Media (5.1) | 4.1% | 💥 Exploit | Dokeos Open Source Learning AND Knowledge Management Tool | 10/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Click-2 Ingenium Learning Management System | 31/12/2002 | 16/6/2026 | Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords. | |
| Modificada | Media (5) | 1.4% | — | Click2learn Ingenium Learning Management System | 31/12/2002 | 16/6/2026 | Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password. |