Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.40% | — | Chamilo LMS | 1/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the home.php component. | |
| Analizada | Alta (7.1) | 0.71% | — | Chamilo LMS | 1/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the new_ticket.php component. | |
| Analizada | Alta (8.8) | 1.1% | — | Emiloimagtolis Online Discussion Forum | 4/10/2024 | 17/6/2026 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded file was received using the "$- FILES" variable | |
| Analizada | Alta (8.8) | 1.1% | — | Emiloimagtolis Online Discussion Forum | 4/10/2024 | 17/6/2026 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded file was received using the "$- FILES" variable. | |
| Analizada | Media (5.1) | 0.61% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The manipulation of the argument prefSeat_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.1) | 0.57% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in itsourcecode Ticket Reservation System 1.0. Affected by this issue is some unknown functionality of the file checkout_ticket_save.php. The manipulation of the argument data leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.65% | — | Emiloimagtolis Ticket Reservation System | 3/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Login Page. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Alta (8.2) | 0.45% | — | Emiloi Online Discussion Forum | 9/7/2024 | 17/6/2026 | SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Analizada | Media (5.3) | 0.75% | — | Emiloimagtolis Online Discussion Forum | 30/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 2.5% | 💥 PoC | Chamilo LMS | 28/11/2023 | 17/6/2026 | Unrestricted file upload in `/main/inc/ajax/work.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | |
| Modificada | Alta (8.8) | 1.8% | — | Chamilo LMS | 28/11/2023 | 17/6/2026 | Unrestricted file upload in `/main/inc/ajax/exercise.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | |
| Modificada | Alta (8.8) | 1.8% | — | Chamilo LMS | 28/11/2023 | 17/6/2026 | Unrestricted file upload in `/main/inc/ajax/dropbox.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | |
| Modificada | Alta (8.8) | 1.8% | — | Chamilo LMS | 28/11/2023 | 17/6/2026 | Unrestricted file upload in `/main/inc/ajax/document.ajax.php` in Chamilo LMS <= v1.11.24 allows authenticated attackers with learner role to obtain remote code execution via uploading of PHP files. | |
| Modificada | Alta (8.8) | 3.5% | — | Chamilo LMS | 28/11/2023 | 17/6/2026 | Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | |
| Modificada | Alta (8.8) | 3.5% | — | Chamilo LMS | 28/11/2023 | 17/6/2026 | Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | |
| Modificada | Media (6.1) | 76% | 💥 Exploit | Chamilo LMS | 28/11/2023 | 17/6/2026 | Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell. | |
| Modificada | Crítica (9.8) | 2.4% | — | Chamilo | 28/11/2023 | 17/6/2026 | Improper sanitisation in `main/inc/lib/fileUpload.lib.php` in Chamilo LMS <= v1.11.20 on Windows and Apache installations allows unauthenticated attackers to bypass file upload security protections and obtain remote code execution via uploading of `.htaccess` file. This vulnerability may be exploited by privileged… | |
| Modificada | Crítica (9.8) | 3.5% | — | Chamilo | 28/11/2023 | 17/6/2026 | Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via arbitrary file write. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Chamilo | 28/11/2023 | 17/6/2026 | Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023-34960. | |
| Modificada | Media (4.9) | 0.73% | — | Chamilo LMS | 1/9/2023 | 17/6/2026 | SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions. | |
| Modificada | Baja (3.5) | 0.28% | — | Chamilo | 21/8/2023 | 9/7/2026 | Cross Site Request Forgery (CSRF) vulnerability in Chamilo v.1.11 thru v.1.11.20 allows a remote authenticated privileged attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 99% | 💥 Exploit | Chamilo | 1/8/2023 | 9/7/2026 | A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the classes/usergroups management section. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the skills wheel. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the session category management section. |