Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.84% | — | Netcad Keos | 31/1/2023 | 17/6/2026 | Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote). | |
| Modificada | Media (5.4) | 0.53% | — | Dokeos | 29/1/2020 | 16/6/2026 | Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php. | |
| Modificada | Media (4.3) | 1.4% | — | Dokeos Project Dokeos | 13/3/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone, (2) Street, (3) Address line, (4) Zip code, or (5) City field to main/auth/profile.php; (6) Subject field to main/social/groups.php; or (7) Message body field to… | |
| Modificada | Alta (7.5) | 2.3% | — | Dokeos | 5/12/2013 | 17/6/2026 | SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Dokeos | 8/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath parameter to main/document/slideshow.php and the (2) file parameter to main/exercice/testheaderpage.php. | |
| Modificada | Media (6.8) | 1.0% | — | Dokeos | 8/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) uInfo parameter to main/tracking/userLog.php and the (2) course parameter to main/mySpace/lp_tracking.php, a different vector than CVE-2009-2006.2. | |
| Modificada | Media (5) | 1.9% | — | Dokeos | 8/6/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a ..\ (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the… | |
| Modificada | Baja (2.6) | 1.3% | — | Dokeos | 8/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) search_term parameter to main/auth/courses.php; the (2) frm_title and (3) frm_content parameters in a new personal agenda item action; the (4) title and… | |
| Modificada | Media (6.8) | 0.66% | — | Dokeos | 8/6/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspecified victims and add new personal agenda items via unknown vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Dokeos | 8/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902. | |
| Modificada | Alta (7.5) | 3.3% | — | Dokeos E-learning System | 30/7/2008 | 16/6/2026 | Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the include parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.4% | — | Dokeos | 21/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header… | |
| Modificada | Media (4.3) | 4.0% | — | Dokeos E-learning System | 21/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Dokeos Open Source Learning AND Knowledge ManagementDokeos Open Source Learning AND Knowledge Management Tool | 28/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php. | |
| Modificada | Media (4.9) | 1.6% | — | Dokeos | 20/12/2007 | 16/6/2026 | Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under… | |
| Modificada | Media (4.3) | 1.8% | — | Dokeos | 30/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the img parameter to main/inc/lib/fckeditor/editor/plugins/ImageManager/editor.php and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Dokeos | 30/5/2007 | 16/6/2026 | SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the course parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 30/5/2007 | 16/6/2026 | SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. | |
| Modificada | Media (5.1) | 10% | — | ClarolineDokeos Open Source Learning AND Knowledge Management Tool | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Dokeos | 28/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos before 1.6.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 6.7% | — | ClarolineDokeos | 10/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php. | |
| Modificada | Media (6.8) | 1.5% | — | DokeosDokeos Community Release | 10/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4)… | |
| Modificada | Media (5.1) | 4.1% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. |