Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.6 LOW
CVE-2026-0995 — Arm C1-Pro TLBI+DSB Memory Access Vulnerability

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

| Memory Corruption
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2025-65465 — Skrol29 TbsZip Reflected Cross-Site Scripting (XSS)

A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earlier allows remote attackers to execute arbitrary web script or HTML via a crafte…

Remote | Cross-Site Scripting
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
7.5 HIGH
CVE-2025-58107 — Microsoft Exchange Samsung EAS Cleartext Data Transmission Vulnerability

In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-…

Remote | Information Disclosure
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
8.3 HIGH
CVE-2025-52482 — Chamilo: Stored XSS in glossary function via /main/glossary/index.php trigger in /main/tr…

Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary function, enabling all users with the Teachers role to inject JavaScript malicious…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2025-50192 — Chamilo: Time-based SQL Injection in /main/webservices/registration.soap.php

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50191 — Chamilo: Error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.…

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched …

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2025-50190 — Chamilo: Error-based SQL Injection via GET openid.assoc_handle with the /index.php script

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET openid.assoc_handle parameter with the /index.php script. This issue has been patc…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.8 HIGH
CVE-2025-50189 — Chamilo: Error-based SQL Injection

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] a…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50188 — Error-based SQL Injection in Chamilo LMS

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following script…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2025-50187 — Chamilo: Evaluation of untrusted user input leads to Remote Code Execution

Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in vers…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.8 MEDIUM
CVE-2025-50186 — Chamilo: Stored XSS via Malicious CSV Filename in user_import.php

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
5.3 MEDIUM
CVE-2024-50337 — Chamilo: Potential unauthenticated blind SSRF via openid function

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This …

chamilo_lms | Remote | Server-Side Request Forgery
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.7 HIGH
CVE-2024-47886 — Chamilo: Post-Auth Remote Code Execution

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing mul…

chamilo_lms | Remote | Authentication
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.9 MEDIUM
CVE-2026-26698 — Code-Projects Simple Student Alumni System SQL Injection

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.

simple_student_alumni_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.9 MEDIUM
CVE-2026-26697 — Code-Projects Simple Student Alumni System SQL Injection Vulnerability

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.

simple_student_alumni_system | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.6 MEDIUM
CVE-2026-1628 — Mattermost allows external websites to open within the app, exposing preload functionalit…

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functiona…

mattermost_server mattermost_desktop | Remote | Misconfiguration
Mar 02, 2026 Mar 05, 2026
Mar 02, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2026-3432 — Sim Studio AI - Unauthenticated OAuth Token Theft

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` pa…

sim | Remote | Authorization
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2026-3431 — Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these end…

sim | Remote | Authentication
Mar 02, 2026 Mar 06, 2026
Mar 02, 2026
Mar 06, 2026
9.8 CRITICAL
CVE-2025-14532 — Remote Code Execution via Unrestricted File Upload in DobryCMS

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue wa…

dorbycms | Remote | Misconfiguration
Mar 02, 2026 Mar 05, 2026
Mar 02, 2026
Mar 05, 2026
9.3 CRITICAL
CVE-2025-12462 — Blind SQL Injection in DobryCMS

A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path resulting in Blind SQL Injection. This issue was fix…

dorbycms | Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
Showing 20 of 5096 Results