Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.80% | — | Personal-management-system Personal Management SystemAI | 27/8/2026 | 24/9/2026 | Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying absolute filesystem paths to the GET /public/get-file/{path} endpoint. The path route parameter is passed directly to file_get_contents() without canonicalization against… | |
| Aplazada | Media (5.4) | 0.22% | — | Personal-management-system Personal Management SystemAI | 22/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the New Goal Creation section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the description parameter. | |
| Aplazada | Media (5.4) | 0.22% | — | Personal-management-system Personal Management SystemAI | 22/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Image Upload section of Volmarg Personal Management System v1.4.65 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the tag parameter. | |
| Analizada | Media (4.7) | 0.21% | — | Personal-management-system Personal Management System | 18/4/2025 | 17/6/2026 | Volmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code and obtain sensitive information via the SameSite cookie attribute defaults value set to none | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function. | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component. | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function. | |
| Analizada | Media (6.5) | 0.38% | — | Personal-management-system Personal Management System | 17/4/2025 | 17/6/2026 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function. | |
| Modificada | Crítica (9.8) | 0.39% | — | Personal-management-system Personal Management System | 5/7/2024 | 17/6/2026 | Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and DNS requests to a server that the attacker controls. | |
| Modificada | Media (5.4) | 0.33% | — | Personal-management-system Personal Management System | 5/7/2024 | 17/6/2026 | Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code. | |
| Modificada | Alta (7.8) | 0.60% | — | Personal-management-system Personal Management System | 4/10/2023 | 17/6/2026 | An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar. | |
| Modificada | Media (6.1) | 0.51% | — | Datev EG Personal-management System Comfort/comfort Plus | 22/6/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in DATEV eG Personal-Management System Comfort/Comfort Plus v15.1.0 to v16.1.1 P4 allows attackers to steal targeted users' login data by sending a crafted link. |