Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.80%—Personal-management-system Personal Management SystemAI27/8/202624/9/2026
Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against…
AplazadaMedia (5.4)0.22%—Personal-management-system Personal Management SystemAI22/4/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter.
AplazadaMedia (5.4)0.22%—Personal-management-system Personal Management SystemAI22/4/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter.
AnalizadaMedia (4.7)0.21%—Personal-management-system Personal Management System18/4/202517/6/2026
Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none
AnalizadaMedia (6.5)0.38%—Personal-management-system Personal Management System17/4/202517/6/2026
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.
AnalizadaMedia (6.5)0.38%—Personal-management-system Personal Management System17/4/202517/6/2026
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
AnalizadaMedia (6.5)0.38%—Personal-management-system Personal Management System17/4/202517/6/2026
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
AnalizadaMedia (6.5)0.38%—Personal-management-system Personal Management System17/4/202517/6/2026
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
ModificadaCrítica (9.8)0.39%—Personal-management-system Personal Management System5/7/202417/6/2026
Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls.
ModificadaMedia (5.4)0.33%—Personal-management-system Personal Management System5/7/202417/6/2026
Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.
ModificadaAlta (7.8)0.60%—Personal-management-system Personal Management System4/10/202317/6/2026
An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.
ModificadaMedia (6.1)0.51%—Datev EG Personal-management System Comfort/comfort Plus22/6/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link.