Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 162 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

335 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.59%—Lopalopa E-learning Management System14/11/202417/6/2026
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
AnalizadaMedia (5.4)0.47%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the d and pi parameters.
AnalizadaMedia (5.4)0.47%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and username parameters.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the school_year parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the date_start, date_end, and title parameters.
AnalizadaMedia (5.4)0.43%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the class_name parameter.
AnalizadaMedia (5.4)0.39%—Lopalopa E-learning Management System14/11/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the subject_code and title parameters.
ModificadaMedia (6.9)0.75%—Viwis Learning Management System13/11/202417/6/2026
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an…
AnalizadaCrítica (9.8)35%💥 PoCVibethemes Wordpress Learning Management System9/11/202417/6/2026
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for…
AnalizadaCrítica (9.8)0.54%—Lang-learn-guy Learning With Texts21/10/202417/6/2026
Learning with Texts (LWT) 2.0.3 is vulnerable to SQL Injection. This occurs when the application fails to properly sanitize user inputs, allowing attackers to manipulate SQL queries by injecting malicious SQL statements into URL parameters. By exploiting this vulnerability, an attacker could gain unauthorized access…
AnalizadaMedia (6.5)0.67%—Learningdigital Orca HCM9/9/202417/6/2026
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.
ModificadaCrítica (9.8)0.68%—Learningdigital Orca HCM9/9/202417/6/2026
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege and subsequently use it to log in.
AnalizadaMedia (5.4)0.29%—Easy Test Online Learning AND Testing Platform Project Easy Test Online Learning AND Testing Platform30/8/202417/6/2026
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.
AnalizadaAlta (8.8)0.67%—Easy Test Online Learning AND Testing Platform Project Easy Test Online Learning AND Testing Platform30/8/202417/6/2026
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.
ModificadaMedia (6.1)0.30%—Lang-learn-guy Learning With Texts21/8/202417/6/2026
Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function that does not filter special characters in URL parameters. Remote attackers can inject JavaScript code without authorization. Exploiting this vulnerability, attackers can steal user credentials or…
ModificadaAlta (8.8)0.68%—Elearningfreak Insert OR Embed Articulate Content15/7/202417/6/2026
The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
AnalizadaCrítica (9.8)0.49%—Itsourcecode Learning Management System9/7/202417/6/2026
SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter.
AnalizadaAlta (8.8)0.54%—Itsourcecode Learning Management System17/6/202417/6/2026
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
ModificadaMedia (5.3)0.50%—Itsourcecode Learning Management System Project IN PHP With Source Code15/6/202417/6/2026
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed…
ModificadaMedia (5.4)0.20%—Elearningfreak Insert OR Embed Articulate Content4/6/202417/6/2026
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
AnalizadaMedia (5.4)0.94%💥 PoCElearningfreak Insert OR Embed Articulate Content4/6/202417/6/2026
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files
AnalizadaMedia (5.3)0.61%—Itsourcecode Learning Management System2/6/202417/6/2026
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (6.9)0.85%—Itsourcecode Learning Management System30/5/202417/6/2026
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaCrítica (9.8)0.85%—Pisay Online E-learning SystemAI17/5/202417/6/2026
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.
AnalizadaAlta (7.3)1.0%—Donbermoy Pisay Online E-learning System30/4/202417/6/2026
A vulnerability has been found in SourceCodester Pisay Online E-Learning System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /lesson/controller.php. The manipulation of the argument file leads to unrestricted upload. The attack can be launched remotely. The…
Orbitaley — Vulnerabilidades