4.8

CVSS3.1

CVE-2025-50186 - Chamilo: Stored XSS via Malicious CSV Filename in user_import.php

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a maliciously named CSV file (e.g., <img src=q onerror=prompt(8)>.csv) that leads to JavaScript execu…

📅 Published: March 2, 2026, 2:36 p.m. 🔄 Last Modified: March 2, 2026, 2:36 p.m.

5.3

CVSS3.1

CVE-2024-50337 - Chamilo: Potential unauthenticated blind SSRF via openid function

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.

📅 Published: March 2, 2026, 2:26 p.m. 🔄 Last Modified: March 2, 2026, 2:26 p.m.

8.7

CVSS4.0

CVE-2024-47886 - Chamilo: Post-Auth Remote Code Execution

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing multiple supported features from the virtualization plugin vchamilo, the vulnerability allows an admini…

📅 Published: March 2, 2026, 2:23 p.m. 🔄 Last Modified: March 2, 2026, 2:23 p.m.

10

CVSS4.0

CVE-2026-23600 -

A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

📅 Published: March 2, 2026, 2:18 p.m. 🔄 Last Modified: March 2, 2026, 2:18 p.m.

4.6

CVSS3.1

CVE-2026-1628 - Mattermost allows external websites to open within the app, exposing preload functionality to non-t…

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Matter…

📅 Published: March 2, 2026, 1:24 p.m. 🔄 Last Modified: March 2, 2026, 2:16 p.m.

9.3

CVSS4.0

CVE-2026-3432 - Sim Studio AI - Unauthenticated OAuth Token Theft

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` parameters. An unauthenticated attacker can retrieve OAuth access tokens for any user by supplying the…

📅 Published: March 2, 2026, 1:01 p.m. 🔄 Last Modified: March 2, 2026, 1:32 p.m.

9.8

CVSS3.1

CVE-2026-3431 - Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including re…

📅 Published: March 2, 2026, 1 p.m. 🔄 Last Modified: March 2, 2026, 1:33 p.m.

9.3

CVSS4.0

CVE-2025-14532 - Remote Code Execution via Unrestricted File Upload in DobryCMS

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0.

📅 Published: March 2, 2026, 12:49 p.m. 🔄 Last Modified: March 2, 2026, 1:34 p.m.

9.3

CVSS4.0

CVE-2025-12462 - Blind SQL Injection in DobryCMS

A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path resulting in Blind SQL Injection. This issue was fixed in versions above 8.0.

📅 Published: March 2, 2026, 12:49 p.m. 🔄 Last Modified: March 2, 2026, 1:35 p.m.

5.3

CVSS4.0

CVE-2025-58406 - Lack of HTTP Response Headers

The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.

📅 Published: March 2, 2026, 11:16 a.m. 🔄 Last Modified: March 2, 2026, 8:29 p.m.
Total resulsts: 335447
Page 15 of 33,545
« previous page » next page
Filters