Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.33% | — | Frappe Learning | 20/2/2026 | 17/6/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.44.0 and below, unauthorized users are able to access the details of unpublished courses via API endpoints. A fix for this issue is planned for the 2.45.0 release. | |
| Aplazada | Alta (8.8) | 0.33% | — | E Learning ScriptAI | 12/2/2026 | 17/6/2026 | E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the… | |
| Analizada | Baja (1.3) | 0.30% | — | Frappe Learning | 11/2/2026 | 17/6/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.44.0, security issue was identified in Frappe Learning, where unauthorised users were able to access the full list of enrolled students (by email) in batches. This vulnerability is fixed in 2.44.0. | |
| Aplazada | Alta (8.8) | 0.41% | — | E-learning PHP ScriptAI | 30/1/2026 | 17/6/2026 | e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information. | |
| Analizada | Baja (2.1) | 0.39% | — | Janobe E-learning System | 19/1/2026 | 17/6/2026 | A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The… | |
| Analizada | Baja (1.3) | 0.17% | — | Frappe Learning | 14/1/2026 | 17/6/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In 2.44.0 and earlier, there is a stored XSS vulnerability where a specially crafted image filename could execute malicious JavaScript when rendered on course or jobs pages. | |
| Analizada | Media (6.5) | 0.32% | — | Learningcircuit Local Deep Research | 23/12/2025 | 17/6/2026 | Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the application's SSRF protection (safe_requests.py). This can allow attackers to… | |
| Aplazada | Media (4.9) | 0.28% | — | Wpindeed Ultimate Learning PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.3. | |
| Aplazada | Alta (8.7) | 0.39% | — | Jheng GAO Student Learning Assessment AND Support SystemAI | 15/12/2025 | 17/6/2026 | Student Learning Assessment and Support System developed by JHENG GAO has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain test accounts and password. | |
| Analizada | Media (5.1) | 0.17% | — | Frappe Learning | 12/12/2025 | 17/6/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allowed authenticated attackers to enter JavaScript through the Company Website field of the Job Form, exposing users to an XSS attack. The script could then be executed in the browsers of… | |
| Analizada | Media (5.1) | 0.17% | — | Frappe Learning | 12/12/2025 | 17/6/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0. | |
| Modificada | Media (6.5) | 0.20% | — | Vibethemes Wordpress Learning Management System | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows DOM-Based XSS.This issue affects WPLMS: from n/a through <= 1.9.9.5.4. | |
| Analizada | Baja (1.3) | 0.21% | — | Frappe Learning | 5/12/2025 | 25/9/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side authorization logic allowed authenticated users to perform actions beyond their assigned roles across multiple features. Because the affected endpoints relied on client-side… | |
| Analizada | Baja (1.2) | 0.17% | — | Frappe Learning | 12/11/2025 | 17/6/2026 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of caching. The issue has been fixed in version 2.41.0 by ensuring the cache is cleared after roles are… | |
| Analizada | Baja (1.3) | 0.21% | — | Frappe Learning | 12/11/2025 | 17/6/2026 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been fixed in version 2.41.0 by ensuring proper roles and redirecting if accessed via direct URL. | |
| Analizada | Baja (1.2) | 0.18% | — | Frappe Learning | 27/10/2025 | 17/6/2026 | Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML through input fields in the Job Form. | |
| Analizada | Baja (1.3) | 0.22% | — | Frappe Learning | 27/10/2025 | 17/6/2026 | Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to access the Quiz Form if they had the URL. | |
| Modificada | Alta (7.1) | 0.25% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows Reflected XSS.This issue affects WPLMS: from n/a through <= 1.9.9.8. | |
| Modificada | Alta (7.5) | 0.36% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7. | |
| Analizada | Baja (2.7) | 0.29% | — | Frappe Learning | 10/10/2025 | 17/6/2026 | Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments uploaded by the students in their assignments as public files. This issue potentially exposed student-uploaded files to the public. Anyone with the file URL could access… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Learning Management System | 9/10/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Analizada | Baja (1.9) | 0.41% | — | Frappe Learning | 5/10/2025 | 17/6/2026 | A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. It is suggested… | |
| Modificada | Baja (1.9) | 0.39% | — | Frappe Learning | 5/10/2025 | 17/6/2026 | A vulnerability was found in Frappe LMS 2.34.x/2.35.0. The impacted element is an unknown function of the component Incomplete Fix CVE-2025-55006. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The affected… | |
| Analizada | Baja (1.3) | 0.36% | — | Frappe Learning | 5/10/2025 | 17/6/2026 | A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished Course Handler. Such manipulation leads to improper access controls. The attack may be launched remotely. This attack is characterized by high complexity. The… | |
| Analizada | Baja (2.9) | 0.48% | — | Frappe Learning | 5/10/2025 | 17/6/2026 | A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is considered difficult. The exploit… |