Common Vulnerabilities and Exposures (CVE)

CVE-2025-50196

Mar 2, 2026 19:20:28 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/editinstance.php via the POST main_database parameter. This issue has been patched in version 1.11.3...

CVE-2026-21853

Mar 2, 2026 19:19:18 UTC

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be exploited by embedding a specially crafted affine: URL on a...

CVE-2025-50195

Mar 2, 2026 19:18:48 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /plugin/vchamilo/views/manage.controller.php. This issue has been patched in version 1.11.30.

CVE-2026-0689

Mar 2, 2026 19:17:37 UTC

In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an authenticated NAC administrator to retrieve masked sensitive parameters from HTTP responses. Although credentials appear...

CVE-2025-50194

Mar 2, 2026 19:15:44 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/cron/lang/check_parse_lang.php. This issue has been patched in version 1.11.30.

CVE-2025-50193

Mar 2, 2026 19:15:12 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /plugin/vchamilo/views/import.php with the POST to_main_database parameter. This issue has been patched in version 1.11.30.

CVE-2025-50192

Mar 2, 2026 19:14:28 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main/webservices/registration.soap.php. This issue has been patched in version 1.11.30.

CVE-2025-47371

Mar 2, 2026 19:13:56 UTC

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

CVE-2025-50191

Mar 2, 2026 19:13:42 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFile with the /main/exercise/hotpotatoes.php script. This issue has been patched in version 1.11.30.

CVE-2025-50197

Mar 2, 2026 19:13:02 UTC

Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /main/admin/sub_language_ajax.inc.php via the POST new_language parameter. This issue has been patched in version 1.11.30.

CVE-2026-26278

Mar 2, 2026 19:11:59 UTC

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of enti...

CVE-2026-25896

Mar 2, 2026 19:11:31 UTC

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard du...

CVE-2025-47373

Mar 2, 2026 19:09:28 UTC

Memory Corruption when accessing buffers with invalid length during TA invocation.

CVE-2026-0654

Mar 2, 2026 19:07:10 UTC

Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration...

CVE-2026-3273

Mar 2, 2026 19:00:02 UTC

A vulnerability was identified in Tenda F453 1.0.0.3. Affected by this vulnerability is the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component httpd. Such manipulation of the argument mit_ssid_index leads to buffe...