6.5

CVSS3.1

CVE-2026-34370 - Chamilo LMS: IDOR in the Notebook Module allows an attacker to view other users' private notes

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated student to read the private course notes of any other user on the platform by manipulating t…

📅 Published: April 14, 2026, 9:25 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7

CVSS4.0

CVE-2026-39907 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via WCF SOAP

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's LFName parameter, allowing remote attackers to trigger SMB connections and leak NTLMv2 machine-accoun…

📅 Published: April 14, 2026, 9:21 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7

CVSS4.0

CVE-2026-39906 - Unisys WebPerfect Image Suite 3.0 NTLMv2 Hash Leakage via .NET Remoting

Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hashes by supplying a Windows UNC path as a target file argument through object-unmarshalling techniques…

📅 Published: April 14, 2026, 9:21 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.8

CVSS3.1

CVE-2026-34631 - InCopy | Out-of-bounds Write (CWE-787)

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

📅 Published: April 14, 2026, 9:14 p.m. 🔄 Last Modified: April 15, 2026, 7:33 p.m.

5.1

CVSS4.0

CVE-2026-34161 - Chamilo LMS: Stored XSS via Malicious File Upload in Social Post Attachments Leads to Arbitrary Jav…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the social post attachment upload functionality, where an authenticated user can upload a malicious HTML file containing JavaScript via the /api/soc…

📅 Published: April 14, 2026, 9:12 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

8.6

CVSS3.1

CVE-2026-34160 - Chamilo LMS: Unauthenticated SSRF via PENS Plugin allows attacker to probe internal network and rea…

Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without authentication and accepts a user-controlled package-url parameter that the server fetche…

📅 Published: April 14, 2026, 9:09 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.2

CVSS3.1

CVE-2026-33715 - Chamilo LMS has Unauthenticated SSRF and Open Email Relay via install.ajax.php test_mailer action

Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include the global.inc.php file that performs authenticat…

📅 Published: April 14, 2026, 9:05 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.1

CVSS4.0

CVE-2026-33714 - Chamilo LMS has Authenticated SQL Injection in statistics.ajax.php users_active action (2.0 RC2)

Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. While CVE-2026-30881 was patched by applying Security::remove_XSS() to the date_start and date_end pa…

📅 Published: April 14, 2026, 9 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.

7.8

CVSS3.1

CVE-2026-27287 - InCopy | Out-of-bounds Read (CWE-125)

InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exp…

📅 Published: April 14, 2026, 8:54 p.m. 🔄 Last Modified: April 15, 2026, 3:58 a.m.

4.8

CVSS4.0

CVE-2026-25133 - October CMS has Stored XSS via SVG Filter Bypass

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the SVG sanitization logic. The regex pattern used to strip event handler attributes (such as onclick or onload) could be bypassed using a …

📅 Published: April 14, 2026, 8:47 p.m. 🔄 Last Modified: April 17, 2026, 3:38 p.m.
Total resulsts: 345139
Page 59 of 34,514
« previous page » next page
Filters