Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.60% | — | EducationAI | 2/7/2025 | 17/6/2026 | The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via deserialization of untrusted input in the 'themerex_callback_view_more_posts' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in… | |
| Analizada | Media (5.3) | 5.2% | — | Hzmanyun Education AND Training System | 4/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the function scorm of the file UploadImageController.java. The manipulation of the argument param leads to command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 5.2% | — | Hzmanyun Education AND Training System | 4/3/2025 | 17/6/2026 | A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this issue is the function exportPDF of the file /user/exportPDF. The manipulation of the argument id leads to command injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 2.4% | — | Hzmanyun Education AND Training System | 25/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. Affected by this vulnerability is the function pdf2swf of the file /pdf2swf. The manipulation of the argument file leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.70% | — | Hzmanyun Education AND Training System | 21/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in hzmanyun Education and Training System 3.1.1. This vulnerability affects the function saveImage. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (4.3) | 0.35% | — | Nicheaddons Education Addon | 19/2/2025 | 17/6/2026 | The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (6.5) | 0.30% | — | Filathemes Education LMSAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FilaThemes Education LMS allows Stored XSS.This issue affects Education LMS: from n/a through 0.0.7. | |
| Modificada | Media (4.3) | 0.18% | — | Rarathemes Education Zone | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in raratheme Education Zone education-zone allows Cross Site Request Forgery.This issue affects Education Zone: from n/a through <= 1.3.4. | |
| Modificada | Media (6.1) | 0.31% | — | Elenazhyvohliad Ucat | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in elenkadark uCAT – Next Story ucat-next-story allows Reflected XSS.This issue affects uCAT – Next Story: from n/a through <= 2.0.0. | |
| Modificada | Media (5.4) | 0.28% | — | Hasthemes WP Education | 20/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DevItems WP Education wp-education allows Stored XSS.This issue affects WP Education: from n/a through <= 1.2.8. | |
| Aplazada | Alta (8.8) | 0.37% | — | Trtek Software Distant Education PlatformAI | 9/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Distant Education Platform allows SQL Injection, Parameter Injection. This issue affects Distant Education Platform: before 3.2024.11. | |
| Modificada | Alta (7.5) | 0.63% | — | Arslansoft Education Portal Project Arslansoft Education Portal | 1/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Read Sensitive Strings Within an Executable. This issue affects Education Portal: before v1.1. | |
| Modificada | Crítica (9.8) | 1.7% | — | Arslansoft Education Portal Project Arslansoft Education Portal | 1/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. This issue affects Education Portal: before v1.1. | |
| Modificada | Alta (7.5) | 0.60% | — | Arslansoft Education Portal Project Arslansoft Education Portal | 1/12/2023 | 17/6/2026 | Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ArslanSoft Education Portal allows Account Footprinting. This issue affects Education Portal: before v1.1. | |
| Modificada | Crítica (9.8) | 0.80% | — | Arslansoft Education Portal Project Arslansoft Education Portal | 1/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Education Portal allows SQL Injection. This issue affects Education Portal: before v1.1. | |
| Modificada | Crítica (9.8) | 0.68% | — | Weblizar School Management - Education & Learning Management | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL Injection.This issue affects The School Management – Education & Learning Management: from n/a through 4.1. | |
| Modificada | Crítica (9.8) | 0.52% | — | Trteksolutions Education Portal | 27/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection. This issue affects Education Portal: before 3.2023.29. | |
| Modificada | Media (5.4) | 0.36% | — | Themepalace TP Education | 18/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Theme Palace TP Education plugin <= 4.4 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Hasthemes WP Education | 27/3/2023 | 17/6/2026 | The WP Education WordPress plugin before 1.2.7 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Crítica (9.8) | 17% | — | Roncoo-education | 26/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file. | |
| Modificada | Alta (8.8) | 0.44% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.42% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.42% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. |