7.6

CVSS3.1

CVE-2026-28403 - Textream Cross-Site WebSocket Hijacking (CSWSH) vulnerability

Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0.1:<httpPort+1>`) accepts connections from any origin without validating the HTTP `Origin` header during the WebSocket handshake. A malicious web page visited in the same browser s…

πŸ“… Published: March 2, 2026, 3:45 p.m. πŸ”„ Last Modified: March 2, 2026, 3:45 p.m.

7.1

CVSS4.0

CVE-2025-50197 - Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_language parame…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:18 p.m. πŸ”„ Last Modified: March 2, 2026, 3:18 p.m.

7.1

CVSS4.0

CVE-2025-50196 - Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_database par…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:17 p.m. πŸ”„ Last Modified: March 2, 2026, 3:17 p.m.

7.1

CVSS4.0

CVE-2025-50195 - Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:16 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

6

CVSS4.0

CVE-2026-0689 - XIQ‑SE NAC Admin Credential Exposure via HTTP Response

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear redacted in the user interface, the application returns th…

πŸ“… Published: March 2, 2026, 3:16 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

7.1

CVSS4.0

CVE-2025-50194 - Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:16 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

7.1

CVSS4.0

CVE-2025-50193 - Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_database p…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 3:16 p.m. πŸ”„ Last Modified: March 2, 2026, 3:16 p.m.

8.8

CVSS4.0

CVE-2025-50192 - Chamilo: Time-based SQL Injection in /main/webservices/registration.soap.php

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 2:54 p.m. πŸ”„ Last Modified: March 2, 2026, 2:54 p.m.

7

CVSS4.0

CVE-2025-50191 - Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 2:53 p.m. πŸ”„ Last Modified: March 2, 2026, 2:53 p.m.

8.8

CVSS4.0

CVE-2025-50190 - Chamilo: Error-based SQL Injection via GET openid.assoc_handle with the /index.php script

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patched in version 1.11.30.

πŸ“… Published: March 2, 2026, 2:53 p.m. πŸ”„ Last Modified: March 2, 2026, 2:53 p.m.
Total resulsts: 335427
Page 12 of 33,543
Β« previous page Β» next page
Filters