Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.21% | — | Wpgrids EasytestAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Grids EasyTest convertpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyTest: from n/a through <= 1.0.1. | |
| Analizada | Alta (8.7) | 0.52% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter. | |
| Analizada | Alta (8.7) | 0.47% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter. | |
| Analizada | Alta (8.7) | 0.47% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter. | |
| Analizada | Alta (8.7) | 0.47% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter. | |
| Analizada | Crítica (9.3) | 0.49% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter. | |
| Analizada | Crítica (9.3) | 0.49% | — | Easytest Online Test Platform | 2/9/2024 | 17/6/2026 | SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters. | |
| Modificada | Media (5.4) | 0.59% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack. | |
| Modificada | Alta (8.8) | 1.1% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions. | |
| Modificada | Alta (8.8) | 1.1% | — | Huaju Easytest Online Learning Test Platform | 15/10/2021 | 17/6/2026 | The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions. |