Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Cluevo Learning Management System | 6/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions. | |
| Analizada | Alta (8.8) | 0.30% | — | Vibethemes Wordpress Learning Management System | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <= 4.900 versions. | |
| Modificada | Crítica (9.8) | 1.4% | — | Fernus Learning Management Systems | 4/4/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Fernus Informatics LMS allows OS Command Injection, Server Side Include (SSI) Injection. This issue affects LMS: before 23.04.03. | |
| Modificada | Media (6.5) | 0.87% | — | Instructure Canvas Learning Management Service | 26/1/2023 | 17/6/2026 | Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url). | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle Learning Management | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management. Successful attacks of… | |
| Modificada | Media (6.1) | 3.0% | 💥 Exploit | Creativeitem Academy Learning Management System | 26/9/2022 | 9/7/2026 | Academy Learning Management System before v5.9.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Search parameter. | |
| Modificada | Media (4.8) | 0.60% | — | Cluevo Learning Management System | 7/2/2022 | 17/6/2026 | The CLUEVO LMS, E-Learning Platform WordPress plugin before 1.8.1 does not sanitise and escape Course's module, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 1.9% | — | Learning Management System Project Learning Management System | 30/7/2021 | 17/6/2026 | Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Learning Management System Project Learning Management System | 23/7/2021 | 17/6/2026 | SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Goodlayers Good Learning Management System | 12/11/2020 | 17/6/2026 | An unauthenticated SQL Injection vulnerability in Good Layers LMS Plugin <= 2.1.4 exists due to the usage of "wp_ajax_nopriv" call in WordPress, which allows any unauthenticated user to get access to the function "gdlr_lms_cancel_booking" where POST Parameter "id" was sent straight into SQL query without sanitization. | |
| Modificada | Media (5.8) | 6.5% | 💥 Exploit | Instructure Canvas Learning Management Service | 21/8/2020 | 17/6/2026 | Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains. | |
| Modificada | Alta (8.2) | 1.3% | — | Oracle Learning Management | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: OTA Training Activities). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning… | |
| Modificada | Media (6.1) | 0.94% | — | Oracle Peoplesoft Enterprise Learning Management | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management component of Oracle PeopleSoft Products (subcomponent: Application Search). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Media (4.3) | 0.83% | — | Oracle Peoplesoft Enterprise Learning Management | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM.… | |
| Modificada | Media (4.3) | 0.65% | — | Wisetail Learning Management System | 12/9/2018 | 17/6/2026 | Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter. | |
| Modificada | Media (4.3) | 0.73% | — | Wisetail Learning Management System | 12/9/2018 | 17/6/2026 | Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Advance Online Learning Management Script Project Advance Online Learning Management Script | 13/12/2017 | 17/6/2026 | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. | |
| Modificada | Media (6.8) | 0.70% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604. | |
| Modificada | Media (4.3) | 1.1% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML… | |
| Modificada | Media (6.8) | 0.62% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies. | |
| Modificada | Media (4.3) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.6 allow remote attackers to inject arbitrary web script or HTML via crafted input. | |
| Modificada | Media (4.3) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter. | |
| Modificada | Media (6) | 1.0% | — | Trivantis Coursemill Learning Management System | 6/9/2013 | 16/6/2026 | Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter. |