Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.36% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username" fields. It allows attackers to inject a… | |
| Analizada | Alta (7.7) | 0.38% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (8.8) | 0.35% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST course_path; POST home_path parameters. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.1) | 2.7% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.1) | 2.8% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.1) | 2.7% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.1) | 2.7% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.1) | 2.7% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (8.3) | 0.38% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious code against the administrator. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (8.8) | 0.60% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7) | 0.56% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (8.8) | 0.60% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30. | |
| Analizada | Alta (7.2) | 0.75% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] and POST login parameters found in /main/coursecopy/copy_course_session_selected.php, which allows an attacker to perform… | |
| Analizada | Alta (7) | 0.74% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following scripts: /plugin/vchamilo/views/syncparams.php and /plugin/vchamilo/ajax/service.php, which allows an attacker to perform an… | |
| Analizada | Crítica (9.8) | 0.90% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in version 1.11.28. | |
| Analizada | Media (4.8) | 0.31% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a maliciously named CSV file (e.g., <img src=q onerror=prompt(8)>.csv) that leads to JavaScript execution when viewed by… | |
| Analizada | Media (5.3) | 0.34% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28. | |
| Analizada | Alta (8.7) | 0.92% | — | Chamilo LMS | 2/3/2026 | 17/6/2026 | Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an administrator to execute… | |
| Analizada | Media (5.5) | 0.59% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Alta (8.7) | 0.39% | — | Chamilo LMSAIElfinderAI | 20/2/2026 | 17/6/2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing… | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sa9000p FirmwareQualcomm Sar2130p FirmwareQualcomm Snapdragon 8 Gen1 5G FirmwareQualcomm Sd662 Firmware+149 | 2/2/2026 | 17/6/2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Analizada | Baja (2.1) | 0.43% | — | Chamilo LMS | 18/1/2026 | 17/6/2026 | A security flaw has been discovered in Chamilo LMS up to 2.0.0 Beta 1. This issue affects the function deleteLegal of the file src/CoreBundle/Controller/SocialController.php of the component Legal Consent Handler. Performing a manipulation of the argument userId results in improper authorization. The attack is… | |
| Analizada | Media (5.5) | 0.24% | 💥 PoC | Chamilo LMS | 16/1/2026 | 17/6/2026 | An issue was discovered in Chamillo LMS 1.11.2. The Social Network /personal_data endpoint exposes full sensitive user information even after logout because proper cache-control is missing. Using the browser back button restores all personal data, allowing unauthorized users on the same device to view confidential… | |
| Analizada | Media (5.5) | 0.48% | — | Emiloi Online Discussion Forum | 22/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Online Discussion Forum 1.0. The impacted element is an unknown function of the file /index.php. Executing manipulation of the argument email/password can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… |