Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.26% | — | Frappe Learning | 9/8/2025 | 17/6/2026 | Frappe Learning is a learning system that helps users structure their content. In versions 2.33.0 and below, the image upload functionality did not adequately sanitize uploaded SVG files. This allowed users to upload SVG files containing embedded JavaScript or other potentially malicious content. Malicious SVG files… | |
| Analizada | Alta (8.8) | 1.6% | — | Vibethemes Wordpress Learning Management System | 19/7/2025 | 17/6/2026 | The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account. | |
| Analizada | Alta (8.8) | 0.68% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.73% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.64% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Media (5.4) | 0.26% | — | Beakon Learning Management System Sharable Content Object Reference Model | 17/7/2025 | 5/7/2026 | Cross Site Scripting vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version V.5.4.3 allows a remote attacker to obtain sensitive information via the URL parameter | |
| Analizada | Crítica (9.8) | 0.70% | — | Beakon Learning Management System Sharable Content Object Reference Model | 23/6/2025 | 17/6/2026 | SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model (SCORM) version before 5.4.3 allows a remote attacker to obtain sensitive information via the ks parameter in json_scorm.php file | |
| Analizada | Media (6.9) | 0.49% | — | Jkev Responsive E-learning System | 27/5/2025 | 17/6/2026 | A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_file.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Alta (8.8) | 0.97% | — | Microsoft Azure Machine Learning | 30/4/2025 | 17/6/2026 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.6) | 0.14% | — | SAP Learning SolutionAI | 22/4/2025 | 17/6/2026 | SAP Learning Solution is vulnerable to Cross-Site Request Forgery (CSRF), allowing an attacker to trick authenticated user into sending unintended requests to the server. GET-based OData function is named in a way that it violates the expected behaviour. This issue could impact both the confidentiality and integrity… | |
| Analizada | Media (5.3) | 0.43% | — | Phpgurukul Elearning System | 24/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.1) | 0.40% | — | Janobe E-learning System | 23/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. | |
| Analizada | Media (5.3) | 0.48% | — | Janobe E-learning System | 23/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. | |
| Analizada | Media (4.9) | 0.40% | — | Wpindeed Ultimate Learning PRO | 21/2/2025 | 17/6/2026 | The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parameter in all versions up to, and including, 3.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.51% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Alta (8.8) | 0.52% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells | |
| Analizada | Crítica (9.8) | 0.58% | — | Learningdigital Orca HCM | 17/2/2025 | 17/6/2026 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user. | |
| Analizada | Crítica (9.8) | 0.72% | — | Jkev Responsive E-learning System | 5/2/2025 | 17/6/2026 | SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field. | |
| Analizada | Alta (7.5) | 0.56% | — | Opigno Learning Path | 9/1/2025 | 17/6/2026 | Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2. | |
| Aplazada | Alta (7.6) | 0.50% | — | Wpindeed Ultimate Learning PROAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9. | |
| Analizada | Media (6.3) | 0.77% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The… | |
| Analizada | Media (5.3) | 0.62% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to… | |
| Analizada | Media (6.9) | 0.57% | — | Kaoshifeng Yunfan Learning Examination System | 2/1/2025 | 17/6/2026 | A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.3) | 0.68% | — | Vibethemes Wordpress Learning Management System | 31/12/2024 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5. | |
| Modificada | Crítica (9.8) | 0.81% | — | Vibethemes Wordpress Learning Management System | 31/12/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS wplms_plugin allows Authentication Bypass.This issue affects WPLMS: from n/a through <= 1.9.9. |