Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.91%—Systrome Cumilon Isg-600c FirmwareSystrome Cumilon Isg-600h FirmwareSystrome Cumilon Isg-800w Firmware21/3/201917/6/2026
An issue was discovered on Systrome ISG-600C, ISG-600H, and ISG-800W 1.1-R2.1_TRUNK-20180914.bin devices. There is CSRF via /ui/?g=obj_keywords_add and /ui/?g=obj_keywords_addsave with resultant XSS because of a lack of csrf token validation.
ModificadaMedia (6.5)0.96%—Chamilo LMS4/2/201917/6/2026
Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable via ticket_id=[ticket number]. This…
ModificadaMedia (6.1)0.80%—Chamilo LMS4/2/201917/6/2026
Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_message.php, main/social/personal_data.php, main/inc/lib/TicketManager.php, main/ticket/ticket_details.php that can result in a message being sent to the Administrator with the XSS to steal cookies.…
ModificadaAlta (8.1)1.2%—Chamilo LMS21/12/201817/6/2026
Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.
ModificadaMedia (5.4)0.66%—Chamilo LMS21/12/201817/6/2026
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
ModificadaMedia (5.4)0.63%—Chamilo LMS21/12/201817/6/2026
Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it…
ModificadaCrítica (9.8)3.2%—Chamilo LMS23/7/201817/6/2026
Chamilo LMS version 11.x contains an Unserialization vulnerability in the "hash" GET parameter for the api endpoint located at /webservices/api/v2.php that can result in Unauthenticated remote code execution. This attack appear to be exploitable via a simple GET request to the api endpoint. This vulnerability appears…
ModificadaMedia (5.8)1.8%—Chamilo Integration Project Chamilo Integration18/8/201517/6/2026
Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.
ModificadaMedia (6)2.7%💥 ExploitChamilo LMS5/12/201317/6/2026
SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.
ModificadaMedia (6.4)3.8%—Miloslav Trmac Libuser22/1/201116/6/2026
libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
ModificadaMedia (4.3)0.84%—Toni Milovan FE Rtenews17/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Frontend news submitter with RTE (fe_rtenews) extension 1.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)7.2%💥 ExploitZoltan Milosevic Fluid Dynamics Search Engine4/10/200216/6/2026
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.
ModificadaMedia (4.6)0.36%—Alpha LinuxAIEclipse MiloAI1/2/199916/6/2026
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.
Orbitaley — Vulnerabilidades