Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Kx00007

#15019of 55,077
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-52136
9.8
2026-06-24
Cacti · Cacti · CVE-2026-39938
**Name of the Vulnerable Software and Affected Versions** Cacti versions prior to 1.2.31 **Description** Cacti is an open source performance and fault management framework. The software contains an unauthenticated Local File Inclusion (LFI), which occurs through the `graph theme` parameter and rrdtool IPC serialization hardening. LFI is a type of vulnerability that allows an attacker to read files on the server that they should not have access to. **Recommendations** Update to version 1.2.31.
PT-2026-32936
8.8
2026-04-14
Unknown · Chamilo Lms · CVE-2026-35196
**Name of the Vulnerable Software and Affected Versions** Chamilo LMS versions prior to 2.0.0-RC.3 **Description** An OS Command Injection issue exists in the 'main/inc/ajax/gradebook.ajax.php' endpoint within the export all certificates action. The course code retrieved from the `$ SESSION[' cid']` session variable via the `api get course id()` function is concatenated directly into a `shell exec()` command string without proper sanitization or escaping. An attacker who can manipulate session data to inject shell metacharacters into the ` cid` variable can execute arbitrary commands on the server, potentially allowing them to read system files and credentials, modify the application and database, or disrupt server availability. **Recommendations** Update to version 2.0.0-RC.3.