Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2022-37159EPSS 25%
Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
Claroline
after 13.5.7
MEDIUM 6.1
CVE-2022-37161
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
Claroline
after 13.5.7
MEDIUM 5.4
CVE-2022-37160
Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privileged user. By combining the X…
Claroline
after 13.5.7
MEDIUM 5.4
CVE-2022-37162
Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution by adding arbitrary javascri…
Claroline
after 13.5.7
MEDIUM 5.0
CVE-2011-3716
Claroline 1.9.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in a…
Claroline
No fix yet
MEDIUM 5.8
CVE-2008-3262
Cross-site request forgery (CSRF) vulnerability in Claroline before 1.8.10 allows remote attackers to change passwords, related to lack of a requirem…
Claroline
after 1.8.9
MEDIUM 5.1
CVE-2007-4718EPSS 7%
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to include and execute arbitrary loca…
Claroline
after 1.8.5
HIGH 7.5
CVE-2006-7048
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) claro…
Claroline
Mitigation only
HIGH 7.5
CVE-2006-5256
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitra…
Claroline
after 1.8.0
MEDIUM 5.1
CVE-2006-4844EPSS 10%
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products…
Claroline
after 1.7.7
MEDIUM 5.1
CVE-2006-2868EPSS 11%
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePa…
Claroline
No fix yet
MEDIUM 6.8
CVE-2006-2284EPSS 7%
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) claro…
Claroline
Patch available
HIGH 7.5
CVE-2006-1594
Multiple directory traversal vulnerabilities in document/rqmkhtml.php in Claroline 1.7.4 and earlier allow remote attackers to use ".." (dot dot) seq…
Claroline
after 1.7.4
HIGH 7.5
CVE-2006-1596
PHP remote file inclusion vulnerability in learnPath/include/scormExport.inc.php in Claroline 1.7.4 and earlier allows remote attackers to execute ar…
Claroline
No fix yet
HIGH 10.0
CVE-2006-0411
claro_init_local.inc.php in Claroline 1.7.2 uses guessable session cookies (MD5 hash of connection time), which allows remote attackers to hijack ses…
Claroline
Mitigation only
HIGH 7.5
CVE-2005-1375
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arb…
Claroline
Patch available
HIGH 7.5
CVE-2005-1376
Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possi…
Claroline
Patch available
HIGH 7.5
CVE-2005-1377
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to…
Claroline
Patch available
MEDIUM 6.8
CVE-2005-1374
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers t…
Claroline
Patch available