Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.99% | — | Chamilo LMS | 15/4/2022 | 17/6/2026 | Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin. | |
| Modificada | Alta (8.8) | 1.1% | — | Chamilo | 21/3/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL. | |
| Modificada | Media (6.8) | 0.85% | — | Chamilo | 21/3/2022 | 17/6/2026 | Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page. | |
| Modificada | Media (5.4) | 0.67% | — | Srmilon WP Google MAP | 25/1/2022 | 17/6/2026 | The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps. | |
| Modificada | Media (4.8) | 0.92% | — | Chamilo LMS | 3/12/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields. | |
| Modificada | Crítica (9.8) | 1.9% | — | Chamilo LMS | 3/12/2021 | 17/6/2026 | Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php. | |
| Modificada | Alta (8.8) | 2.6% | — | Chamilo LMS | 3/12/2021 | 17/6/2026 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file. | |
| Modificada | Media (6.1) | 1.2% | — | Chamilo | 1/12/2021 | 9/7/2026 | chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie. | |
| Modificada | Media (6.1) | 0.58% | — | Chamilo LMS | 3/11/2021 | 17/6/2026 | Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends. | |
| Modificada | Media (5.4) | 2.1% | 💥 Exploit | Chamilo LMS | 10/8/2021 | 17/6/2026 | A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send… | |
| Modificada | Media (6.1) | 0.81% | — | Chamilo LMS | 10/8/2021 | 17/6/2026 | A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature). | |
| Modificada | Media (6.1) | 1.0% | — | Chamilo | 10/8/2021 | 17/6/2026 | Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter. | |
| Modificada | Crítica (9.8) | 16% | 💥 Exploit | Chamilo | 28/6/2021 | 17/6/2026 | main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter. | |
| Modificada | Media (6.5) | 1.7% | — | Chamilo | 13/5/2021 | 17/6/2026 | admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. | |
| Modificada | Media (4.9) | 0.90% | — | Chamilo LMS | 6/5/2021 | 17/6/2026 | Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege. | |
| Modificada | Alta (8.8) | 0.78% | 💥 PoC | Chamilo LMS | 6/5/2021 | 17/6/2026 | Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user. | |
| Modificada | Alta (7.2) | 14% | 💥 Exploit | Chamilo | 30/4/2021 | 17/6/2026 | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code… | |
| Modificada | Media (6.1) | 0.99% | — | Chamilo | 19/2/2021 | 17/6/2026 | Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. | |
| Modificada | Media (6.1) | 1.4% | — | Chamilo | 8/2/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action. | |
| Modificada | Media (6.1) | 0.80% | — | Chamilo | 30/1/2020 | 16/6/2026 | Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script. | |
| Modificada | Media (6.1) | 0.80% | — | Chamilo | 30/1/2020 | 16/6/2026 | Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Chamilo LMS | 10/1/2020 | 16/6/2026 | Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files. | |
| Modificada | Media (6.1) | 0.68% | — | Chamilo LMS | 4/1/2020 | 17/6/2026 | Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503. | |
| Modificada | Crítica (9.8) | 4.0% | — | Chamilo LMS | 30/6/2019 | 17/6/2026 | Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder… | |
| Modificada | Alta (7.8) | 1.3% | — | Systrome Cumilon Isg-600c FirmwareSystrome Cumilon Isg-600h FirmwareSystrome Cumilon Isg-800w Firmware | 21/3/2019 | 17/6/2026 | An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command… |