Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.27% | 💥 PoC | Vishalmathur Cloudclassroom | 31/7/2025 | 17/6/2026 | CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking… | |
| Analizada | Media (6.5) | 0.24% | 💥 PoC | Vishalmathur Cloudclassroom | 31/7/2025 | 17/6/2026 | A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization. | |
| Modificada | Media (6.5) | 0.30% | 💥 PoC | Vishalmathur Cloudclassroom-php Project | 25/7/2025 | 5/7/2026 | CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter. | |
| Analizada | Crítica (9.8) | 0.59% | — | Vishalmathur Cloudclassroom-php Project | 20/6/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries. | |
| Analizada | Crítica (9.8) | 0.57% | 💥 PoC | Vishalmathur Cloudclassroom-php Project | 18/6/2025 | 17/6/2026 | CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network… | |
| Analizada | Crítica (9.8) | 0.63% | 💥 PoC | Vishalmathur Cloudclassroom-php Project | 18/6/2025 | 17/6/2026 | CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers to inject arbitrary SQL payloads and… | |
| Analizada | Media (6.1) | 0.39% | 💥 PoC | Vishalmathur Cloudclassroom-php Project | 9/6/2025 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement. | |
| Analizada | Alta (7.3) | 1.1% | 💥 Exploit | Vishalmathur Cloudclassroom-php Project | 2/6/2025 | 17/6/2026 | SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries. | |
| Analizada | Alta (7.3) | 0.24% | — | Vishalmathur Cloudclassroom-php Project | 2/6/2025 | 17/6/2026 | A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands. | |
| Analizada | Media (6.1) | 0.49% | — | Vishalmathur Cloudclassroom-php Project | 26/2/2025 | 17/6/2026 | A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function. | |
| Analizada | Media (5.1) | 0.47% | — | Classroombookings | 10/10/2024 | 17/6/2026 | A vulnerability was found in Craig Rodway Classroombookings 2.8.7 and classified as problematic. This issue affects some unknown processing of the file /sessions of the component Session Page. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. Upgrading to… | |
| Analizada | Media (5.3) | 0.46% | — | Classroombookings | 10/10/2024 | 17/6/2026 | A vulnerability has been found in Craig Rodway Classroombookings up to 2.8.6 and classified as problematic. This vulnerability affects unknown code of the file /rooms/fields of the component Room Page. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Media (6.1) | 0.41% | — | Braincert Virtual Classroom API | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BrainCert BrainCert – HTML5 Virtual Classroom allows Reflected XSS.This issue affects BrainCert – HTML5 Virtual Classroom: from n/a through 1.30. | |
| Modificada | Crítica (9.8) | 0.60% | — | Braincert Virtual Classroom | 7/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | |
| Modificada | Media (6.1) | 0.46% | — | Classroombookings | 20/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in craigrodway classroombookings 2.6.4 allows attackers to execute arbitrary code or other unspecified impacts via the input bgcol in file Weeks.php. | |
| Modificada | Crítica (9.8) | 0.66% | — | Classroom-engagement-system Project Classroom-engagement-system | 12/1/2023 | 16/6/2026 | A vulnerability was found in aeharding classroom-engagement-system and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection. The attack may be launched remotely. The name of the patch is 096de5815c7b414e7339f3439522a446098fb73a. It is recommended to… | |
| Modificada | Alta (7.2) | 1.0% | — | Classroombookings | 14/12/2020 | 17/6/2026 | SQL Injection in Classbooking before 2.4.1 via the username field of a CSV file when adding a new user. |