Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Oracle Learning Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful… | |
| Analizada | Alta (7.3) | 0.33% | — | Oracle Learning Management | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Learning Management. Successful… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the… | |
| Analizada | Alta (8.8) | 0.43% | — | King-products Learning Management System King | 19/6/2026 | 19/8/2026 | Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and… | |
| Analizada | Baja (2.1) | 0.23% | — | Frappe Learning | 10/6/2026 | 23/7/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain user-editable fields that, when surfaced in page metadata, caused visitors' browsers to navigate to an attacker-chosen… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester Onlne Examination AND Learning Management SystemAISourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026… | |
| Aplazada | Media (5) | 0.41% | — | Learningcircuit Local Deep ResearchAI | 28/5/2026 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The current project uses validate_url to validate the input URL. The main logic is to… | |
| Aplazada | Media (5) | 0.36% | — | Learningcircuit Local Deep ResearchAI | 28/5/2026 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from research.title or research.query) and metadata key-value pairs — directly into an… | |
| Aplazada | Crítica (9.4) | 0.45% | — | Frappe Learning Management SystemAI | 20/5/2026 | 23/7/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Azure Machine Learning | 12/5/2026 | 18/6/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Azure Machine Learning | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Alta (8) | 0.43% | — | Totara LearningAI | 13/4/2026 | 17/6/2026 | Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser. NOTE: The supplier states that the… | |
| Analizada | Media (5.3) | 0.28% | — | Frappe Learning | 8/4/2026 | 24/7/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, a vulnerability has been identified in Frappe Learning where quiz scores can be modified by students before submission. The application currently relies on client-side calculated scores, which can be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Campcodes Complete Online Learning Management SystemAI | 5/4/2026 | 24/7/2026 | A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Analizada | Media (6.9) | 0.33% | — | Frappe Learning | 2/4/2026 | 24/7/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. From version 2.27.0 to before version 2.48.0, Frappe LMS was vulnerable to stored XSS. This issue has been patched in version 2.48.0. | |
| Analizada | Baja (2.7) | 0.48% | — | Aicentre Federated Learning AND Interoperability Platform | 27/3/2026 | 17/6/2026 | Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks.… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Simple E-learning SystemAI | 23/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Simple E-learning SystemAI | 23/3/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.47% | — | Jcharis Machine-learning-web-appsAIPocoo Jinja2AI | 11/3/2026 | 17/6/2026 | A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such… | |
| Aplazada | Alta (7.1) | 0.26% | — | Wpindeed Ultimate Learning PROAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Reflected XSS.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.1. |