AMI vendor intelligence

AMI Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting AMI products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse AMI KEVs Full KEV feed
Total KEVs
7
Known exploited vulnerabilities affecting AMI products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
6
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
AMI KEV with sensor-observed exploitation activity

The catalog gap matters for AMI exposure

Six of the seven exploited AMI CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 86% of this vendor portfolio.

14%
Covered by CISA
86%
Beyond CISA
5
Product families

Attested AMI CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-45298

Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webhook (default no-auth deploy)

dozzle Confirmed Beyond CISA 16 Aug 2026
CVE-2021-34187

main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.

Chamilo LMS High Beyond CISA 12 Nov 2025
CVE-2023-34960

A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands...

Chamilo High Beyond CISA 07 Jul 2025
CVE-2022-25369

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a...

Dynamicweb High Beyond CISA 06 Jun 2025
CVE-2024-54085

Redfish Authentication Bypass

MegaRAC-SPx Confirmed In CISA 01 Jun 2026
CVE-2023-4220

Chamilo LMS Unauthenticated Big Upload File Remote Code Execution

Chamilo High Beyond CISA 28 Nov 2023
CVE-2023-3368

Chamilo LMS Unauthenticated Command Injection

Chamilo High Beyond CISA 28 Nov 2023

Showing 7 of 7 AMI known exploited vulnerabilities.

Recurring weakness patterns

Authentication, authentication bypass using an alternate path or channel, and authentication bypass by spoofing account for three mapped occurrences across this AMI KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.