Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.43% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an Insecure Direct Object Reference (IDOR) vulnerability in the Learning Path progress saving endpoint. The file lp_ajax_save_item.php accepts a uid (user ID) parameter directly from $_REQUEST and uses it to load and… | |
| Analizada | Crítica (9.3) | 0.58% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, a chained attack can enable otherwise-blocked PHP code from the main/install/ directory and allow an unauthenticated attacker to modify existing files or create new files where allowed by system permissions. This only affects portals with the main/install/… | |
| Analizada | Alta (8.8) | 0.56% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to .0.0-RC.3, the PlatformConfigurationController::decodeSettingArray() method uses PHP's eval() to parse platform settings from the database. An attacker with admin access (obtainable via Advisory 1) can inject arbitrary PHP code into the settings, which is then… | |
| Analizada | Media (6.5) | 0.23% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the REST API stats endpoint allows any authenticated user (including low-privilege students with ROLE_USER) to read any other user's learning progress, certificates, and gradebook scores for… | |
| Analizada | Media (6.1) | 0.31% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulnerability in the session course edit page allows an attacker to redirect an authenticated administrator to an arbitrary external URL after saving coach assignment changes. The redirect also leaks the id_session parameter… | |
| Analizada | Alta (8.8) | 0.91% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an unrestricted file upload vulnerability in the exercise sound upload function allows an authenticated teacher to upload a PHP webshell by spoofing the Content-Type header to audio/mpeg. The uploaded file retains its original .php extension… | |
| Analizada | Alta (7.1) | 0.34% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook evaluation edit page allows any authenticated teacher to view and modify the settings (name, max score, weight) of evaluations belonging to any other course by… | |
| Analizada | Alta (7.1) | 0.44% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Object Reference (IDOR) vulnerability in the gradebook result view page allows any authenticated teacher to delete any student's grade result across the entire platform by manipulating the delete_mark or resultdelete GET… | |
| Analizada | Media (5.4) | 0.24% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting (XSS) vulnerability in the exercise question list admin panel allows an attacker to execute arbitrary JavaScript in an authenticated teacher's browser. The pagination code merges all $_GET parameters via array_merge()… | |
| Analizada | Alta (8.8) | 2.7% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path values directly into exec() shell commands without using escapeshellarg(). When a… | |
| Analizada | Media (6.5) | 0.40% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a Server-Side Request Forgery (SSRF) vulnerability in the Social Wall feature. The endpoint read_url_with_open_graph accepts a URL from the user via the social_wall_new_msg_main POST parameter and performs two… | |
| Analizada | Alta (8.8) | 0.45% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3. | |
| Analizada | Alta (8.3) | 0.53% | — | Chamilo LMS | 10/4/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exercise/savescores.php leading to arbitrary file feletion. User input from $_REQUEST['test'] is concatenated directly into filesystem path without canonicalization or traversal checks. This vulnerability is fixed in… | |
| Analizada | Media (4.7) | 0.17% | — | Chamilo LMS | 10/4/2026 | 7/10/2026 | Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicious redirect through the use of the redirect parameter to /login. This vulnerability is fixed in 2.0-beta.2. | |
| Analizada | Alta (7.5) | 0.15% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+99 | 6/4/2026 | 17/6/2026 | Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection. | |
| Analizada | Alta (7.5) | 0.20% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+146 | 6/4/2026 | 17/6/2026 | Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans. | |
| Analizada | Alta (8.8) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+150 | 6/4/2026 | 7/10/2026 | Memory corruption when decoding corrupted satellite data files with invalid signature offsets. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+97 | 6/4/2026 | 7/10/2026 | Memory corruption while processing a frame request from user. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+177 | 6/4/2026 | 7/10/2026 | Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation. | |
| Analizada | Media (6.1) | 0.26% | — | Chamilo LMS | 16/3/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Chamilo LMS version 1.11.34 and prior contains a Reflected Cross-Site Scripting (XSS) vulnerability in the session category listing page. The keyword parameter from $_REQUEST is echoed directly into an HTML href attribute without any encoding or sanitization. An attacker… | |
| Analizada | Alta (8.8) | 0.47% | — | Chamilo LMS | 16/3/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Version 1.11.34 and prior contains a SQL Injection vulnerability in the statistics AJAX endpoint. The parameters date_start and date_end from $_REQUEST are embedded directly into a raw SQL string without proper sanitization. Although Database::escape_string() is called… | |
| Analizada | Media (6.3) | 0.34% | — | Chamilo LMS | 16/3/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36. | |
| Analizada | Alta (8.8) | 0.88% | — | Chamilo LMS | 16/3/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .htaccess or PHP files… | |
| Analizada | Crítica (9.3) | 0.59% | — | Chamilo LMS | 16/3/2026 | 17/6/2026 | Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a predictable legacy password reset mechanism, an attacker can achieve… | |
| Analizada | Alta (8.8) | 1.1% | 💥 PoC | Chamilo LMS | 6/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote code execution vulnerability caused by improper validation of uploaded files. The application relies solely on MIME-type verification when handling file uploads and does not adequately validate file… |