Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2025-50189 — Chamilo: Error-based SQL Injection

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the POST resource[document][SQL_INJECTION_HERE] a…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
7.0 HIGH
CVE-2025-50188 — Error-based SQL Injection in Chamilo LMS

Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of data coming from the user from the GET value parameter with the following script…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2025-50187 — Chamilo: Evaluation of untrusted user input leads to Remote Code Execution

Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filtering which leads to Remote Code Execution. This issue has been patched in vers…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
4.8 MEDIUM
CVE-2025-50186 — Chamilo: Stored XSS via Malicious CSV Filename in user_import.php

Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exists due to insufficient sanitization of CSV filenames. An attacker can upload a…

Remote | Cross-Site Scripting
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2024-50337 — Chamilo: Potential unauthenticated blind SSRF via openid function

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This …

Remote | Server-Side Request Forgery
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
8.7 HIGH
CVE-2024-47886 — Chamilo: Post-Auth Remote Code Execution

Chamilo is a learning management system. Chamillo is affected by a post-authentication phar unserialize which leads to a remote code execution (RCE) within versions 1.11.12 to 1.11.26. By abusing mul…

Remote | Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
4.9 MEDIUM
CVE-2026-26698 — Code-Projects Simple Student Alumni System SQL Injection

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
4.9 MEDIUM
CVE-2026-26697 — Code-Projects Simple Student Alumni System SQL Injection Vulnerability

code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
4.6 MEDIUM
CVE-2026-1628 — Mattermost allows external websites to open within the app, exposing preload functionalit…

Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functiona…

mattermost_server | Remote | Misconfiguration
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2026-3432 — Sim Studio AI - Unauthenticated OAuth Token Theft

On SimStudio version below to 0.5.74, the `/api/auth/oauth/token` endpoint contains a code path that bypasses all authorization checks when provided with `credentialAccountUserId` and `providerId` pa…

sim | Remote | Authorization
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.8 CRITICAL
CVE-2026-3431 — Sim Studio AI - MongoDB SSRF and Arbitrary Document Deletion

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these end…

sim | Remote | Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2025-14532 — Remote Code Execution via Unrestricted File Upload in DobryCMS

DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue wa…

Remote | Misconfiguration
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.3 CRITICAL
CVE-2025-12462 — Blind SQL Injection in DobryCMS

A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path resulting in Blind SQL Injection. This issue was fix…

Remote | Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2025-58406 — Lack of HTTP Response Headers

The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, a…

Remote | Misconfiguration
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
5.3 MEDIUM
CVE-2025-58405 — Lack of protection mechanisms against Clickjacking attacks

The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detected. As a result, an…

Remote | Cross-Site Request Forgery
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
7.1 HIGH
CVE-2025-58402 — Insecure Direct Object Reference Message ID

The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker can access messages…

Remote | Authorization
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
6.9 MEDIUM
CVE-2025-30062 — SQL injection in CheckUnitCodeAndKey.pl

In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.

| Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.4 CRITICAL
CVE-2025-30044 — RCE on uhcapache user permissions

In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-bin/CliniNET.prd/utils/userlogstat2.pl", and "/cgi-bin/CliniNET.prd/utils/dblog…

| Injection
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.0 CRITICAL
CVE-2025-30042 — Session generation possible with certificate number only

The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verifica…

| Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
9.0 CRITICAL
CVE-2025-30035 — Lack of API authentication allowing session generation for any user

The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any oth…

| Authentication
Mar 02, 2026 Mar 02, 2026
Mar 02, 2026
Mar 02, 2026
Showing 20 of 4859 Results