Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.1%💥 ExploitIproject Management System Project Iproject Management System29/10/201717/6/2026
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
ModificadaMedia (4.3)1.6%—PS Project Management Team Unity-firefox-extension26/12/201216/6/2026
content/unity-api.js in the unity-firefox-extension extension 2.4.1 for Firefox exposes the toDataURL function in an API call, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted webpage.
ModificadaAlta (7.5)1.9%—PS Project Management Team Libunity-webapps30/11/201216/6/2026
Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables."
ModificadaAlta (7.5)3.5%—PS Project Management Team Unity-firefox-extension24/11/201216/6/2026
Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.
ModificadaMedia (6.8)6.2%💥 ExploitPhppm PHP Project Management23/10/200716/6/2026
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the def_lang parameter to modules/files/list.php; the m_path parameter to (2) modules/projects/summary.inc.php or (3)…
ModificadaMedia (6.8)40%💥 ExploitPhppm PHP Project Management23/10/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the full_path parameter to (1) certinfo/index.php, (2) emails/index.php, (3) events/index.php, (4) fax/index.php, (5) files/index.php, (6) files/list.php,…
ModificadaAlta (7.5)3.4%💥 ExploitUeberproject Management System26/10/200616/6/2026
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.
Orbitaley — Vulnerabilidades