Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters. | |
| Analizada | Media (5.4) | 0.43% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 14/11/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters. | |
| Modificada | Media (6.9) | 0.75% | — | Viwis Learning Management System | 13/11/2024 | 17/6/2026 | A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an… | |
| Analizada | Crítica (9.8) | 35% | 💥 PoC | Vibethemes Wordpress Learning Management System | 9/11/2024 | 17/6/2026 | The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for… | |
| Analizada | Crítica (9.8) | 0.49% | — | Itsourcecode Learning Management System | 9/7/2024 | 17/6/2026 | SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter. | |
| Analizada | Alta (8.8) | 0.54% | — | Itsourcecode Learning Management System | 17/6/2024 | 17/6/2026 | SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter. | |
| Modificada | Media (5.3) | 0.50% | — | Itsourcecode Learning Management System Project IN PHP With Source Code | 15/6/2024 | 17/6/2026 | A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.61% | — | Itsourcecode Learning Management System | 2/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.85% | — | Itsourcecode Learning Management System | 30/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.26% | — | Cluevo Learning Management System | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions. | |
| Analizada | Alta (8.8) | 0.30% | — | Vibethemes Wordpress Learning Management System | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Fernus Learning Management Systems | 4/4/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03. | |
| Modificada | Media (6.1) | 3.0% | 💥 Exploit | Creativeitem Academy Learning Management System | 26/9/2022 | 9/7/2026 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |
| Modificada | Media (4.8) | 0.60% | — | Cluevo Learning Management System | 7/2/2022 | 17/6/2026 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 1.9% | — | Learning Management System Project Learning Management System | 30/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Learning Management System Project Learning Management System | 23/7/2021 | 17/6/2026 | SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Goodlayers Good Learning Management System | 12/11/2020 | 17/6/2026 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization. | |
| Modificada | Media (4.3) | 0.65% | — | Wisetail Learning Management System | 12/9/2018 | 17/6/2026 | Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter. | |
| Modificada | Media (4.3) | 0.73% | — | Wisetail Learning Management System | 12/9/2018 | 17/6/2026 | Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter. | |
| Modificada | Media (6.8) | 0.70% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML… | |
| Modificada | Media (6.8) | 0.62% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies. |