Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_subject.php. Executing manipulation of the argument subject_code can lead to sql injection. The attack may be performed from remote. The exploit has been…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/class.php. Performing manipulation of the argument class_name results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System22/9/202517/6/2026
A vulnerability was identified in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_class.php. Such manipulation of the argument class_name leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System1/9/202517/6/2026
A vulnerability was found in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /teacher_signup.php. Performing manipulation of the argument firstname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. Other…
AnalizadaMedia (5.5)0.42%—Campcodes Online Learning Management System1/9/202517/6/2026
A vulnerability was detected in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /student_signup.php. The manipulation of the argument Username results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
AnalizadaMedia (5.5)0.41%—Campcodes Online Learning Management System1/9/202517/6/2026
A weakness has been identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /login.php. This manipulation of the argument Username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be…
AnalizadaMedia (5.5)0.41%—Campcodes Online Learning Management System31/8/202517/6/2026
A security flaw has been discovered in Campcodes Online Learning Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and…
AnalizadaAlta (8.8)1.6%—Vibethemes Wordpress Learning Management System19/7/202517/6/2026
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
ModificadaMedia (5.4)0.26%—Beakon Learning Management System Sharable Content Object Reference Model17/7/20255/7/2026
Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter
AnalizadaCrítica (9.8)0.70%—Beakon Learning Management System Sharable Content Object Reference Model23/6/202517/6/2026
SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file
ModificadaCrítica (9.3)0.68%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
ModificadaCrítica (9.8)0.81%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1.9.9.
ModificadaCrítica (9.8)0.63%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS wplms_plugin allows Privilege Escalation.This issue affects WPLMS: from n/a through <= 1.9.9.
ModificadaCrítica (9.8)0.76%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through <= 1.9.9.
ModificadaCrítica (9.8)0.70%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
ModificadaAlta (8.8)0.56%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.48%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.58%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.44%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
ModificadaAlta (8.8)0.69%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.46%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.
ModificadaAlta (8.8)0.69%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
ModificadaAlta (8.5)0.47%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.
ModificadaAlta (8.8)0.60%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.
ModificadaAlta (8.8)0.62%—Vibethemes Wordpress Learning Management System18/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.3.
Orbitaley — Vulnerabilidades