Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.59% | — | Kodezen Academy LMS | 14/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25. | |
| Modificada | Alta (8.8) | 0.44% | — | Kodezen Academy LMS | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16. | |
| Modificada | Alta (8.8) | 0.76% | — | Kodezen Academy LMS | 13/3/2024 | 17/6/2026 | The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.9.19. This is due to plugin allowing arbitrary user meta updates through the saved_user_info() function. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 5.3% | 💥 Exploit | Creativeitem Academy LMS | 15/9/2023 | 17/6/2026 | A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely.… | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Creativeitem Academy LMS | 15/9/2023 | 17/6/2026 | A vulnerability was found in Academy LMS 6.2 on Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument… | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Creativeitem Academy LMS | 4/8/2023 | 17/6/2026 | Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 3.8% | 💥 Exploit | Creativeitem Academy LMS | 3/8/2023 | 17/6/2026 | A vulnerability has been found in Academy LMS 6.0 and classified as problematic. This vulnerability affects unknown code of the file /academy/home/courses. The manipulation of the argument query/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-235966 is the identifier assigned to this… | |
| Modificada | Media (6.1) | 0.36% | — | Creativeitem Academy LMS | 19/7/2023 | 17/6/2026 | A vulnerability was found in Creativeitem Academy LMS 5.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home/courses. The manipulation of the argument sort_by leads to cross site scripting. The attack may be launched remotely. VDB-234422 is the identifier… | |
| Modificada | Alta (8.8) | 0.86% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows attackers to arbitrarily add Administrator users. | |
| Modificada | Media (4.8) | 0.41% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows an attacker to arbitrarily create a page. | |
| Modificada | Media (4.3) | 0.62% | 💥 PoC | Creativeitem Academy LMS | 3/2/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Academy LMS before v5.10 allows a discount coupon to be arbitrarily created if an attacker with administrative privileges interacts on the CSRF page. | |
| Modificada | Media (4.8) | 0.62% | 💥 PoC | Creativeitem Academy LMS | 25/5/2022 | 17/6/2026 | Academy-LMS v4.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the SEO panel. |