Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-24112 — Tenda W20E Buffer Overflow Vulnerability

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value of `userInfo`. When `userInfo` is passed into the `addWewifiWhiteUser` functio…

w20e_firmware w20e | Remote | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-24110 — Tenda W20E Buffer Overflow

An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addDhcpRule` function and are processed by `ret = sscanf(pRule…

w20e_firmware w20e | Remote | Memory Corruption
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.8 CRITICAL
CVE-2026-24101 — Tenda AC15V1.0 Command Injection Vulnerability

An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` will be passed into sub_B0488, concatenated into `doSystemCmd`. The value of s1_1…

ac15_firmware ac15 | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.0 MEDIUM
CVE-2026-0689 — XIQ‑SE NAC Admin Credential Exposure via HTTP Response

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HT…

Remote | Information Disclosure
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
6.1 MEDIUM
CVE-2025-66880 — Wethink Technology Inc 720yun Pano-sdk Cross Site Scripting Vulnerability

Cross Site Scripting vulnerability in Wethink Technology Inc 720yun pano-sdk 0.5.877 allows a remote attacker to execute arbitrary code via the LoginComp (Module 2093) and SignupComp (Module 2094) mo…

Remote | Cross-Site Scripting
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2025-52998 — Chamilo: PHAR deserialization bypass

Chamilo is a learning management system. Prior to version 1.11.30, in the application, deserialization of data is performed, the data can be spoofed. An attacker can create objects of arbitrary class…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.9 MEDIUM
CVE-2025-52564 — Chamilo: HTML injection via open parameter

Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as unde…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-52563 — Chamilo: Reflected XSS via page parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-52476 — Chamilo: Reflected XSS via keyword_active parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
6.1 MEDIUM
CVE-2025-52475 — Chamilo: Reflected XSS via keyword_inactive parameter

Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
4.8 MEDIUM
CVE-2025-52470 — Chamilo: Stored Cross-Site Scripting (XSS) via Session Category Name

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists in the session_category_add.php script. The vulnerability is caused by impr…

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.1 HIGH
CVE-2025-52469 — Chamilo: Friend Request Workflow Bypass - Unauthorized Friend Addition and ID Validation …

Chamilo is a learning management system. Prior to version 1.11.30, a logic vulnerability in the friend request workflow of Chamilo’s social network module allows an authenticated user to forcibly add…

chamilo_lms | Remote | Authorization
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.8 HIGH
CVE-2025-52468 — Chamilo: Stored XSS Vulnerability via CSV User Import

Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization …

chamilo_lms | Remote | Cross-Site Scripting
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
9.1 CRITICAL
CVE-2025-50199 — Chamilo: Blind Server-Side Request Forgery (Unauth Blind SSRF)

Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via the POST openid_url parameter. This issue has been patched in version 1.11.30.

chamilo_lms | Remote | Server-Side Request Forgery
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
8.8 HIGH
CVE-2025-50198 — Chamilo: Deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST …

Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted data in /plugin/vchamilo/views/import.php via POST configuration_file; POST co…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50197 — Chamilo: OS Command Injection in /main/admin/sub_language_ajax.inc.php via POST new_langu…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This is…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50196 — Chamilo: OS Command Injection in /plugin/vchamilo/views/editinstance.php via POST main_da…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50195 — Chamilo: OS Command Injection in /plugin/vchamilo/views/manage.controller.php

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in versi…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50194 — Chamilo: OS Command Injection in /main/cron/lang/check_parse_lang.php

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
7.2 HIGH
CVE-2025-50193 — Chamilo: OS command Injection in /plugin/vchamilo/views/import.php with the POST to_main_…

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This i…

chamilo_lms | Remote | Injection
Mar 02, 2026 Mar 03, 2026
Mar 02, 2026
Mar 03, 2026
Showing 20 of 5070 Results