Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

238 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.99%—Chamilo LMS15/4/202217/6/2026
Chamilo LMS v1.11.13 lacks validation on the user modification form, allowing attackers to escalate privileges to Platform Admin.
ModificadaAlta (8.8)1.1%—Chamilo21/3/202217/6/2026
A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.
ModificadaMedia (6.8)0.85%—Chamilo21/3/202217/6/2026
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction with the attacker's profile page.
ModificadaMedia (5.4)0.67%—Srmilon WP Google MAP25/1/202217/6/2026
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
ModificadaMedia (4.8)0.92%—Chamilo LMS3/12/202117/6/2026
A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the course "Title" and "Content" fields.
ModificadaCrítica (9.8)1.9%—Chamilo LMS3/12/202117/6/2026
Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload.php.
ModificadaAlta (8.8)2.6%—Chamilo LMS3/12/202117/6/2026
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
ModificadaMedia (6.1)1.2%—Chamilo1/12/20219/7/2026
chamilo-lms v1.11.14 is affected by a Cross Site Scripting (XSS) vulnerability in /plugin/jcapture/applet.php if an attacker passes a message hex2bin in the cookie.
ModificadaMedia (6.1)0.58%—Chamilo LMS3/11/202117/6/2026
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
ModificadaMedia (5.4)2.1%💥 ExploitChamilo LMS10/8/202117/6/2026
A user without privileges in Chamilo LMS 1.11.14 can send an invitation message to another user, e.g., the administrator, through main/social/search.php, main/inc/lib/social.lib.php and steal cookies or execute arbitrary code on the administration side via a stored XSS vulnerability via social network the send…
ModificadaMedia (6.1)0.81%—Chamilo LMS10/8/202117/6/2026
A Chamilo LMS 1.11.14 reflected XSS vulnerability exists in main/social/search.php=q URI (social network search feature).
ModificadaMedia (6.1)1.0%—Chamilo10/8/202117/6/2026
Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.
ModificadaCrítica (9.8)16%💥 ExploitChamilo28/6/202117/6/2026
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.
ModificadaMedia (6.5)1.7%—Chamilo13/5/202117/6/2026
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
ModificadaMedia (4.9)0.90%—Chamilo LMS6/5/202117/6/2026
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
ModificadaAlta (8.8)0.78%💥 PoCChamilo LMS6/5/202117/6/2026
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
ModificadaAlta (7.2)14%💥 ExploitChamilo30/4/202117/6/2026
A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a parameter used for file uploads, and improper file-extension filtering for certain filenames (e.g., .phar or .pht). A remote authenticated administrator is able to upload a file containing arbitrary PHP code…
ModificadaMedia (6.1)0.99%—Chamilo19/2/202117/6/2026
Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI.
ModificadaMedia (6.1)1.4%—Chamilo8/2/202016/6/2026
Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.
ModificadaMedia (6.1)0.80%—Chamilo30/1/202016/6/2026
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.
ModificadaMedia (6.1)0.80%—Chamilo30/1/202016/6/2026
Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.
ModificadaAlta (7.5)1.3%—Chamilo LMS10/1/202016/6/2026
Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.
ModificadaMedia (6.1)0.68%—Chamilo LMS4/1/202017/6/2026
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
ModificadaCrítica (9.8)4.0%—Chamilo LMS30/6/201917/6/2026
Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It extracts a ZIP archive before checking its content, and once it has been extracted, does not check files in a recursive way. This means that by putting a .php file in a folder and then this folder…
ModificadaAlta (7.8)1.3%—Systrome Cumilon Isg-600c FirmwareSystrome Cumilon Isg-600h FirmwareSystrome Cumilon Isg-800w Firmware21/3/201917/6/2026
An issue was discovered on Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W devices with firmware V1.1-R2.1_TRUNK-20181105.bin. A shell command injection occurs by editing the description of an ISP file. The file network/isp/isp_update_edit.php does not properly validate user input, which leads to shell command…