Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.16% | — | Intel Hardware-aware-automated-machine-learning | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Simple E-learning SystemAI | 23/3/2026 | 17/6/2026 | A vulnerability was detected in SourceCodester Simple E-learning System 1.0. This vulnerability affects unknown code of the component User Profile Update Handler. The manipulation of the argument firstName results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. | |
| Aplazada | Baja (2.1) | 0.32% | — | Sourcecodester Simple E-learning SystemAI | 23/3/2026 | 17/6/2026 | A security vulnerability has been detected in SourceCodester Simple E-learning System 1.0. This affects an unknown part of the file /includes/form_handlers/delete_post.php of the component HTTP GET Parameter Handler. The manipulation of the argument post_id leads to sql injection. It is possible to initiate the attack… | |
| Aplazada | Baja (2.1) | 0.47% | — | Jcharis Machine-learning-web-appsAIPocoo Jinja2AI | 11/3/2026 | 17/6/2026 | A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such… | |
| Aplazada | Alta (8.8) | 0.41% | — | E-learning PHP ScriptAI | 30/1/2026 | 17/6/2026 | e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information. | |
| Analizada | Baja (2.1) | 0.39% | — | Janobe E-learning System | 19/1/2026 | 17/6/2026 | A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The… | |
| Analizada | Media (5.5) | 0.48% | — | Jkev Responsive E-learning System | 18/9/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /admin/add_teacher.php. The manipulation of the argument Username results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.9) | 0.43% | — | Youth-is-as-pale-as-poetry E-learningAI | 18/9/2025 | 30/9/2026 | A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\JwtUtils.java of the component JWT Token Handler. The manipulation leads to insufficiently random values. The attack can… | |
| Analizada | Media (6.9) | 0.49% | — | Jkev Responsive E-learning System | 27/5/2025 | 17/6/2026 | A vulnerability was found in projectworlds Responsive E-Learning System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_file.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.40% | — | Janobe E-learning System | 23/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. | |
| Analizada | Media (5.3) | 0.48% | — | Janobe E-learning System | 23/2/2025 | 17/6/2026 | A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. | |
| Analizada | Crítica (9.8) | 0.72% | — | Jkev Responsive E-learning System | 5/2/2025 | 17/6/2026 | SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field. | |
| Analizada | Alta (7.5) | 0.56% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads. | |
| Analizada | Crítica (9.8) | 0.51% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. | |
| Analizada | Crítica (9.8) | 0.51% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. | |
| Analizada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, | |
| Analizada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter. | |
| Analizada | Crítica (9.8) | 0.60% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters. | |
| Analizada | Crítica (9.8) | 0.92% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php. | |
| Analizada | Media (5.4) | 0.39% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. | |
| Modificada | Alta (7.2) | 0.49% | — | Lopalopa E-learning Management System | 9/12/2024 | 17/6/2026 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php. |