Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.21%—Wpgrids EasytestAI31/12/202517/6/2026
Missing Authorization vulnerability in WP Grids EasyTest convertpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EasyTest: from n/a through <= 1.0.1.
AnalizadaAlta (8.7)0.52%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
AnalizadaAlta (8.7)0.47%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
AnalizadaAlta (8.7)0.47%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
AnalizadaAlta (8.7)0.47%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
AnalizadaCrítica (9.3)0.49%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
AnalizadaCrítica (9.3)0.49%—Easytest Online Test Platform2/9/202417/6/2026
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
ModificadaMedia (4.3)0.84%—Huaju Easytest Online Learning Test Platform15/10/202117/6/2026
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.
ModificadaMedia (5.4)0.59%—Huaju Easytest Online Learning Test Platform15/10/202117/6/2026
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
ModificadaAlta (8.8)1.1%—Huaju Easytest Online Learning Test Platform15/10/202117/6/2026
The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions.
ModificadaAlta (8.8)1.1%—Huaju Easytest Online Learning Test Platform15/10/202117/6/2026
The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.