Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

134 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters.
AnalizadaMedia (5.4)0.43%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters.
ModificadaMedia (6.9)0.75%—Viwis Learning Management System13/11/202417/6/2026
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an…
AnalizadaCrítica (9.8)35%💥 PoCVibethemes Wordpress Learning Management System9/11/202417/6/2026
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for…
AnalizadaCrítica (9.8)0.49%—Itsourcecode Learning Management System9/7/202417/6/2026
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.
AnalizadaAlta (8.8)0.54%—Itsourcecode Learning Management System17/6/202417/6/2026
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
ModificadaMedia (5.3)0.50%—Itsourcecode Learning Management System Project IN PHP With Source Code15/6/202417/6/2026
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.61%—Itsourcecode Learning Management System2/6/202417/6/2026
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.85%—Itsourcecode Learning Management System30/5/202417/6/2026
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaAlta (8.8)0.26%—Cluevo Learning Management System6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.
AnalizadaAlta (8.8)0.30%—Vibethemes Wordpress Learning Management System11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
ModificadaCrítica (9.8)1.4%—Fernus Learning Management Systems4/4/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03.
ModificadaMedia (6.1)3.0%💥 ExploitCreativeitem Academy Learning Management System26/9/20229/7/2026
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
ModificadaMedia (4.8)0.60%—Cluevo Learning Management System7/2/202217/6/2026
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)1.9%—Learning Management System Project Learning Management System30/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
ModificadaAlta (7.5)1.5%—Learning Management System Project Learning Management System23/7/202117/6/2026
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.
ModificadaCrítica (9.8)10%💥 ExploitGoodlayers Good Learning Management System12/11/202017/6/2026
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.
ModificadaMedia (4.3)0.65%—Wisetail Learning Management System12/9/201817/6/2026
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.
ModificadaMedia (4.3)0.73%—Wisetail Learning Management System12/9/201817/6/2026
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
ModificadaMedia (6.8)0.70%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605.
ModificadaMedia (4.3)1.1%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604.
ModificadaMedia (4.3)1.1%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML…
ModificadaMedia (6.8)0.62%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies.
Orbitaley — Vulnerabilidades