Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Frappe Learning Management SystemAI | 17/9/2026 | 23/9/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its… | |
| Aplazada | Media (5.3) | 0.22% | — | Sourcecodester Onlne Examination & Learning Management SystemAI | 18/8/2026 | 20/8/2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely. | |
| Aplazada | Media (5.3) | 0.35% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely. | |
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination & Learning Management SystemAI | 6/7/2026 | 6/7/2026 | A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 5/7/2026 | 7/7/2026 | A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.5) | 0.50% | — | Sourcecodester Online Examination Learning Management SystemAI | 5/7/2026 | 6/7/2026 | A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed… | |
| Analizada | Alta (8.8) | 0.43% | — | King-products Learning Management System King | 19/6/2026 | 19/8/2026 | Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and… | |
| Aplazada | Media (5.5) | 0.29% | — | Sourcecodester Onlne Examination AND Learning Management SystemAISourcecodester Syllabus-aligned Learning Management AND Examination SystemAI | 8/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026… | |
| Aplazada | Crítica (9.4) | 0.45% | — | Frappe Learning Management SystemAI | 20/5/2026 | 23/7/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with course editing role could upload a SCORM ZIP package to write files outside the intended directory. This issue has been resolved in version 2.50.1. | |
| Aplazada | Baja (2.1) | 0.35% | — | Campcodes Complete Online Learning Management SystemAI | 5/4/2026 | 24/7/2026 | A flaw has been found in Campcodes Complete Online Learning Management System 1.0. This impacts the function add_lesson of the file /application/models/Crud_model.php. This manipulation causes unrestricted upload. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Modificada | Media (6.5) | 0.20% | — | Vibethemes Wordpress Learning Management System | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows DOM-Based XSS.This issue affects WPLMS: from n/a through <= 1.9.9.5.4. | |
| Modificada | Alta (7.1) | 0.25% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VibeThemes WPLMS wplms_plugin allows Reflected XSS.This issue affects WPLMS: from n/a through <= 1.9.9.8. | |
| Modificada | Alta (7.5) | 0.36% | — | Vibethemes Wordpress Learning Management System | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.7. | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Learning Management System | 9/10/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the file /admin/calendar_of_events.php. The manipulation of the argument date_start results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 28/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/school_year.php. The manipulation of the argument school_year results in sql injection. It is possible to launch the attack remotely. The exploit has been released to… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Learning Management System | 28/9/2025 | 17/6/2026 | A weakness has been identified in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/edit_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.42% | — | Campcodes Online Learning Management System | 27/9/2025 | 17/6/2026 | A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 27/9/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Learning Management System 1.0. This impacts an unknown function of the file /admin/edit_teacher.php. Performing manipulation of the argument department results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 27/9/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Online Learning Management System 1.0. This affects an unknown function of the file /admin/de_activate.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 27/9/2025 | 17/6/2026 | A security flaw has been discovered in Campcodes Online Learning Management System 1.0. Impacted is an unknown function of the file /admin/teachers.php. The manipulation of the argument department results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.48% | — | Campcodes Online Learning Management System | 27/9/2025 | 17/6/2026 | A vulnerability was identified in Campcodes Online Learning Management System 1.0. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the argument d leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be… |