Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

335 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.26%—Frappe Learning9/8/202517/6/2026
Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files…
AnalizadaAlta (8.8)1.6%—Vibethemes Wordpress Learning Management System19/7/202517/6/2026
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
AnalizadaAlta (8.8)0.68%—Microsoft Azure Machine Learning18/7/202517/6/2026
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.73%—Microsoft Azure Machine Learning18/7/202517/6/2026
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.64%—Microsoft Azure Machine Learning18/7/202517/6/2026
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
ModificadaMedia (5.4)0.26%—Beakon Learning Management System Sharable Content Object Reference Model17/7/20255/7/2026
Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter
AnalizadaCrítica (9.8)0.70%—Beakon Learning Management System Sharable Content Object Reference Model23/6/202517/6/2026
SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file
AnalizadaMedia (6.9)0.49%—Jkev Responsive E-learning System27/5/202517/6/2026
A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_file.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaAlta (8.8)0.97%—Microsoft Azure Machine Learning30/4/202517/6/2026
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (4.6)0.14%—SAP Learning SolutionAI22/4/202517/6/2026
SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity…
AnalizadaMedia (5.3)0.43%—Phpgurukul Elearning System24/3/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.1)0.40%—Janobe E-learning System23/2/202517/6/2026
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
AnalizadaMedia (5.3)0.48%—Janobe E-learning System23/2/202517/6/2026
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.
AnalizadaMedia (4.9)0.40%—Wpindeed Ultimate Learning PRO21/2/202517/6/2026
The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AnalizadaAlta (8.8)0.51%—Learningdigital Orca HCM17/2/202517/6/2026
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaAlta (8.8)0.52%—Learningdigital Orca HCM17/2/202517/6/2026
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells
AnalizadaCrítica (9.8)0.58%—Learningdigital Orca HCM17/2/202517/6/2026
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
AnalizadaCrítica (9.8)0.72%—Jkev Responsive E-learning System5/2/202517/6/2026
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.
AnalizadaAlta (7.5)0.56%—Opigno Learning Path9/1/202517/6/2026
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.
AplazadaAlta (7.6)0.50%—Wpindeed Ultimate Learning PROAI7/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9.
AnalizadaMedia (6.3)0.77%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The…
AnalizadaMedia (5.3)0.62%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to…
AnalizadaMedia (6.9)0.57%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.3)0.68%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
ModificadaCrítica (9.8)0.81%—Vibethemes Wordpress Learning Management System31/12/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1.9.9.
Orbitaley — Vulnerabilidades