Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.26%—Cluevo Learning Management System6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions.
AnalizadaAlta (8.8)0.30%—Vibethemes Wordpress Learning Management System11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions.
ModificadaCrítica (9.8)1.4%—Fernus Learning Management Systems4/4/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03.
ModificadaMedia (6.5)0.87%—Instructure Canvas Learning Management Service26/1/202317/6/2026
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
ModificadaAlta (7.5)0.52%—Oracle Learning Management18/1/202317/6/2026
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of…
ModificadaMedia (6.1)3.0%💥 ExploitCreativeitem Academy Learning Management System26/9/20229/7/2026
Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter.
ModificadaMedia (4.8)0.60%—Cluevo Learning Management System7/2/202217/6/2026
The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)1.9%—Learning Management System Project Learning Management System30/7/202117/6/2026
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
ModificadaAlta (7.5)1.5%—Learning Management System Project Learning Management System23/7/202117/6/2026
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.
ModificadaCrítica (9.8)10%💥 ExploitGoodlayers Good Learning Management System12/11/202017/6/2026
An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization.
ModificadaMedia (5.8)6.5%💥 ExploitInstructure Canvas Learning Management Service21/8/202017/6/2026
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
ModificadaAlta (8.2)1.3%—Oracle Learning Management15/4/202017/6/2026
Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: OTA Training Activities). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning…
ModificadaMedia (6.1)0.94%—Oracle Peoplesoft Enterprise Learning Management23/4/201917/6/2026
Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management component of Oracle PeopleSoft Products (subcomponent: Application Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…
ModificadaMedia (4.3)0.83%—Oracle Peoplesoft Enterprise Learning Management23/4/201917/6/2026
Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM.…
ModificadaMedia (4.3)0.65%—Wisetail Learning Management System12/9/201817/6/2026
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.
ModificadaMedia (4.3)0.73%—Wisetail Learning Management System12/9/201817/6/2026
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
ModificadaCrítica (9.8)3.0%💥 ExploitAdvance Online Learning Management Script Project Advance Online Learning Management Script13/12/201717/6/2026
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.
ModificadaMedia (6.8)0.70%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605.
ModificadaMedia (4.3)1.1%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604.
ModificadaMedia (4.3)1.1%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML…
ModificadaMedia (6.8)0.62%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies.
ModificadaMedia (4.3)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.6 allow remote attackers to inject arbitrary web script or HTML via crafted input.
ModificadaMedia (4.3)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
ModificadaAlta (7.5)1.3%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter.
ModificadaMedia (6)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.