6.3

CVSS4.0

CVE-2026-30876 - Chamilo LMS: User enumeration vulnerability via response

Chamilo LMS is a learning management system. Prior to version 1.11.36, Chamilo is vulnerable to user enumeration with valid/invalid username. This issue has been patched in version 1.11.36.

📅 Published: March 16, 2026, 7:18 p.m. 🔄 Last Modified: March 17, 2026, 6:53 p.m.

8.8

CVSS3.1

CVE-2026-30875 - Chamilo LMS: Authenticated RCE via H5P Import

Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package validation only checks if h5p.json exists but doesn't block .h…

📅 Published: March 16, 2026, 7:16 p.m. 🔄 Last Modified: March 17, 2026, 6:53 p.m.

9.3

CVSS4.0

CVE-2026-28430 - Chamilo LMS Vulnerable to Unauthenticated SQL Injection in chamiko-lms model.ajax.php

Chamilo LMS is a learning management system. Prior to version 1.11.34, there is an unauthenticated SQL injection vulnerability which allows remote attackers to execute arbitrary SQL commands via the custom_dates parameter. By chaining this with a predictable legacy password reset mechanism, an atta…

📅 Published: March 16, 2026, 7:13 p.m. 🔄 Last Modified: March 17, 2026, 6:53 p.m.

6.9

CVSS4.0

CVE-2026-29516 - Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure

Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on …

📅 Published: March 16, 2026, 7:07 p.m. 🔄 Last Modified: March 17, 2026, 4:16 p.m.

7.7

CVSS4.0

CVE-2026-32267 - Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithT…

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->ac…

📅 Published: March 16, 2026, 7:04 p.m. 🔄 Last Modified: March 18, 2026, 3:43 p.m.

8.6

CVSS4.0

CVE-2026-32264 - Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and al…

📅 Published: March 16, 2026, 7:02 p.m. 🔄 Last Modified: March 17, 2026, 5:53 p.m.

8.6

CVSS4.0

CVE-2026-32263 - Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handler…

📅 Published: March 16, 2026, 6:57 p.m. 🔄 Last Modified: March 17, 2026, 5:55 p.m.

5.3

CVSS4.0

CVE-2026-32262 - Craft CMS has a Path Traversal Vulnerability in AssetsController

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call before Assets::prepareA…

📅 Published: March 16, 2026, 6:57 p.m. 🔄 Last Modified: March 17, 2026, 5:56 p.m.

8.5

CVSS4.0

CVE-2026-32261 - RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin

Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without san…

📅 Published: March 16, 2026, 6:50 p.m. 🔄 Last Modified: March 17, 2026, 9:52 a.m.

7.4

CVSS4.0

CVE-2025-69196 - FastMCP OAuth Proxy token reuse across MCP servers

FastMCP is the standard framework for building MCP applications. Prior to version 2.14.2, the server does not properly respect the resource parameter submitted by the client in the authorization and token request. Instead of issuing the token explicitly for the MCP server, the token is issued for t…

📅 Published: March 16, 2026, 6:07 p.m. 🔄 Last Modified: March 18, 2026, 3:11 p.m.
Total resulsts: 339045
Page 81 of 33,905
« previous page » next page
Filters