Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters. | |
| Analizada | Media (5.4) | 0.43% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters. | |
| Aplazada | Crítica (9.8) | 0.85% | — | Pisay Online E-learning SystemAI | 17/5/2024 | 17/6/2026 | An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Alta (7.3) | 1.0% | — | Donbermoy Pisay Online E-learning System | 30/4/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The… | |
| Modificada | Alta (7.5) | 0.74% | — | Simple E-learning System Project Simple E-learning System | 7/11/2022 | 17/6/2026 | An information disclosure vulnerability in the component vcs/downloadFiles.php?download=./search.php of Simple E-Learning System v1.0 allows attackers to read arbitrary files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Simple E-learning System Project Simple E-learning System | 7/10/2022 | 17/6/2026 | An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode. | |
| Modificada | Alta (7.5) | 0.82% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as problematic. This vulnerability affects unknown code of the file downloadFiles.php. The manipulation of the argument download leads to information disclosure. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.54% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affects unknown code of the file /claire_blake. The manipulation of the argument Bio leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 0.67% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /claire_blake. The manipulation of the argument phoneNumber leads to sql injection. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.75% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file search.php. The manipulation of the argument searchPost leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.64% | — | Simple E-learning System Project Simple E-learning System | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System. It has been classified as critical. Affected is an unknown function of the file comment_frame.php. The manipulation of the argument post_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.58% | — | Simple E-learning System Project Simple E-learning System | 5/8/2022 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerability is an unknown functionality of the file classroom.php. The manipulation of the argument post_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.78% | — | Simple E-learning System Project Simple E-learning System | 20/7/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x74666264 WHERE 5610=5610 AND (SELECT 7504 FROM(SELECT… | |
| Modificada | Alta (8.8) | 0.78% | — | Simple E-learning System Project Simple E-learning System | 20/7/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Simple E-Learning System 1.0. It has been rated as critical. This issue affects some unknown processing of the file classRoom.php. The manipulation of the argument classCode with the input 1'||(SELECT 0x6770715a WHERE 8795=8795 AND (SELECT 8342 FROM(SELECT… | |
| Modificada | Media (5.4) | 0.56% | — | Simple E-learning System Project Simple E-learning System | 14/7/2022 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vulnerability is an unknown functionality of the file /vcs/claire_blake. The manipulation of the argument Bio with the input "><script>alert(document.cookie)</script> leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 18% | 💥 Exploit | E-learning System Project E-learning System | 15/2/2021 | 17/6/2026 | E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell. | |
| Modificada | Crítica (9.8) | 6.0% | — | Pisay Online E-learning System Project Pisay Online E-learning System | 22/6/2020 | 17/6/2026 | Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentication and achieve Remote Code Execution (RCE) via the user_email, user_pass, and id parameters on the admin login-portal and the edit-lessons webpages. | |
| Modificada | Alta (7.5) | 1.3% | — | Preprojects PRE E-learning Portal | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter. | |
| Modificada | Media (5) | 1.3% | — | Preprojects PRE E-learning Portal | 4/2/2009 | 16/6/2026 | PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Dokeos E-learning System | 30/7/2008 | 16/6/2026 | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Dokeos E-learning System | 21/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to… |