Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition. | |
| Modificada | Media (4.8) | 0.38% | — | Chamilo | 7/7/2023 | 17/6/2026 | Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section. | |
| Modificada | Crítica (9.8) | 1.1% | — | Chamilo LMS | 13/6/2023 | 9/7/2026 | An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file. | |
| Modificada | Alta (8.1) | 0.74% | — | Chamilo LMS | 8/6/2023 | 17/6/2026 | Incorrect access control in Chamilo v1.11.x up to v1.11.18 allows a student to arbitrarily access and modify another student's personal notes. | |
| Modificada | Media (6.1) | 0.40% | — | Chamilo LMS | 8/6/2023 | 17/6/2026 | Chamilo v1.11.x up to v1.11.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the /feedback/comment field. | |
| Modificada | Media (5.3) | 0.61% | — | Chamilo LMS | 8/6/2023 | 17/6/2026 | An issue in Chamilo v1.11.* up to v1.11.18 allows attackers to execute a Server-Side Request Forgery (SSRF) and obtain information on the services running on the server via crafted requests in the social and links tools. | |
| Modificada | Media (4.3) | 0.41% | — | Chamilo LMS | 8/6/2023 | 17/6/2026 | Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID. | |
| Modificada | Media (5.4) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the personal notes function. | |
| Modificada | Media (5.4) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via a crafted payload to the My Progress function. | |
| Modificada | Media (4.8) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local authenticated attacker to execute arbitrary code via the homepage function. | |
| Modificada | Media (5.4) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the course category parameters. | |
| Modificada | Media (4.8) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the resource sequencing parameters. | |
| Modificada | Media (5.4) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skype and linedin_url parameters. | |
| Modificada | Media (6.1) | 0.43% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the skills wheel parameter. | |
| Modificada | Media (5.4) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the forum title parameter. | |
| Modificada | Media (4.8) | 0.42% | — | Chamilo LMS | 9/5/2023 | 9/7/2026 | Cross Site Scripting vulnerability found in Chamilo Lms v.1.11.18 allows a local attacker to execute arbitrary code via the system annnouncements parameter. | |
| Modificada | Alta (8.8) | 0.76% | — | Chamilo | 17/10/2022 | 17/6/2026 | Chamilo 1.11.16 is affected by an authenticated local file inclusion vulnerability which allows authenticated users with access to 'big file uploads' to copy/move files from anywhere in the file system into the web directory. | |
| Modificada | Alta (8.8) | 1.6% | — | Chamilo | 29/9/2022 | 17/6/2026 | A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a crafted Zip file. | |
| Modificada | Alta (7.5) | 1.3% | — | Eclipse Milo | 8/9/2022 | 17/6/2026 | The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False. | |
| Modificada | Alta (8.8) | 0.85% | — | Chamilo LMS | 15/4/2022 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file. | |
| Modificada | Media (6.1) | 0.60% | — | Chamilo | 15/4/2022 | 17/6/2026 | Chamilo LMS v1.11.13 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /blog/blog.php. | |
| Modificada | Crítica (9.8) | 0.99% | — | Chamilo LMS | 15/4/2022 | 17/6/2026 | Chamilo LMS v1.11.13 was discovered to contain a SQL injection vulnerability via the blog_id parameter at /blog/blog.php. | |
| Modificada | Media (6.1) | 0.60% | — | Chamilo LMS | 15/4/2022 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Chamilo LMS v1.11.13 allows attackers to execute arbitrary web scripts or HTML via user interaction with a crafted URL. |