Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 473 respecto a la semana anterior
Críticas / altas1452▲ 235 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.28% | — | Phpunit Project Phpunit | 8/5/2026 | 17/6/2026 | PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the… | |
| Analizada | Alta (7.8) | 0.39% | — | Phpunit Project PhpunitDebian Linux | 27/1/2026 | 17/6/2026 | PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Phpunit Project PhpunitOracle Communications Diameter Signaling Router | 27/6/2017 | 17/6/2026 | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the… | |
| Modificada | Media (4.3) | 1.4% | — | Phpunit Project Phpunit | 1/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the PHPUnit extension before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 2.7% | — | Perlunity Phpunity.newsmanager | 2/3/2010 | 16/6/2026 | Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. | |
| Modificada | Alta (7.5) | 6.6% | — | Perlunity Phpunity Postcard | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter. |