Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.38% | — | Erudika ScooldAI | 17/9/2026 | 30/9/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/controllers/QuestionController.java in QuestionController.reply() and… | |
| Aplazada | Media (6.5) | 0.40% | — | Erudika ScooldAI | 17/9/2026 | 24/9/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access because src/main/java/com/erudika/scoold/api/ApiController.java in ApiController.getPostReplies() does not apply canAccessSpace before… | |
| Aplazada | Media (6.7) | 0.43% | — | Erudika ScooldAI | 8/5/2026 | 17/6/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configuration value to be modified through /api/config/set/admins with a forged Bearer token that is accepted as an admin API token. Once that setting is changed, the target email address is written to the… | |
| Analizada | Media (6.5) | 0.31% | — | Erudika Scoold | 7/4/2026 | 24/7/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.66.2, an authenticated authorization flaw in Scoold allows any logged-in, low-privilege user to overwrite another user's existing question by supplying that question's public ID as the postId parameter to POST /questions/ask. Because question IDs… | |
| Analizada | Media (6.5) | 0.48% | — | Erudika Scoold | 2/4/2026 | 24/7/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.66.1, Scoold contains an authenticated authorization flaw in feedback deletion that allows any logged-in, low-privilege user to delete another user's feedback post by submitting its ID to POST /feedback/{id}/delete. The handler enforces… | |
| Analizada | Alta (8.7) | 1.0% | — | Erudika Scoold | 29/10/2024 | 17/6/2026 | Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive configuration data. Furthermore, PUT requests on the… | |
| Modificada | Alta (8.8) | 1.1% | — | Erudika Scoold | 29/4/2022 | 17/6/2026 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server. | |
| Modificada | Media (5.4) | 0.57% | — | Erudika Scoold | 18/2/2022 | 17/6/2026 | Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to a XSS attack when using uppercase letters. |