Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.38%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.
AnalizadaAlta (7.2)0.38%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.
AnalizadaAlta (7.2)0.38%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.
AnalizadaAlta (7.2)0.38%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.
AnalizadaAlta (7.2)0.47%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
AnalizadaCrítica (9.8)0.49%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
ModificadaMedia (4.8)0.56%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and lastname parameters.
AnalizadaAlta (7.2)0.59%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
AnalizadaAlta (7.2)0.59%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
AnalizadaCrítica (9.8)0.60%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
AnalizadaAlta (7.2)0.59%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
AnalizadaMedia (5.4)0.47%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the d and pi parameters.
AnalizadaMedia (5.4)0.47%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and username parameters.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters.
AnalizadaMedia (5.4)0.43%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters.
ModificadaMedia (6.9)0.75%—Viwis Learning Management System13/11/202417/6/2026
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an…
AnalizadaCrítica (9.8)35%💥 PoCVibethemes Wordpress Learning Management System9/11/202417/6/2026
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for…
AnalizadaCrítica (9.8)0.49%—Itsourcecode Learning Management System9/7/202417/6/2026
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.
AnalizadaAlta (8.8)0.54%—Itsourcecode Learning Management System17/6/202417/6/2026
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
ModificadaMedia (5.3)0.50%—Itsourcecode Learning Management System Project IN PHP With Source Code15/6/202417/6/2026
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.61%—Itsourcecode Learning Management System2/6/202417/6/2026
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.85%—Itsourcecode Learning Management System30/5/202417/6/2026
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.68%—Weblizar School Management - Education & Learning Management6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar The School Management – Education & Learning Management allows SQL Injection.This issue affects The School Management – Education & Learning Management: from n/a through 4.1.