Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

134 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.6 allow remote attackers to inject arbitrary web script or HTML via crafted input.
ModificadaMedia (4.3)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.
ModificadaAlta (7.5)1.3%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter.
ModificadaMedia (6)1.0%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.
ModificadaAlta (8.5)1.5%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions.
ModificadaAlta (9.3)1.9%—Trivantis Coursemill Learning Management System6/9/201316/6/2026
userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html.
ModificadaAlta (7.5)1.4%—Trivantis Coursemill Enterprise Learning Management System15/12/200716/6/2026
SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)1.4%—Click2learn Ingenium Learning Management System31/12/200216/6/2026
Click2Learn Ingenium Learning Management System 5.1 and 6.1 stores the hashed administrative password in a config.txt file under the htdocs directory, which allows remote attackers to obtain the administrative password.
ModificadaAlta (7.5)6.3%💥 ExploitClick-2 Ingenium Learning Management System31/12/200216/6/2026
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords.