Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)1.2%—Pragyan CMS Project Pragyan CMS19/9/201717/6/2026
Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in Information Disclosure.
ModificadaMedia (4.9)1.2%—Pragyan CMS Project Pragyan CMS19/9/201717/6/2026
Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in Information Disclosure.
ModificadaCrítica (9.8)1.0%—Pragyan CMS Project Pragyan CMS7/9/201717/6/2026
SQL injection vulnerability in Pragyan CMS 3.0.
ModificadaAlta (7.5)3.8%—Pragyan CMS Project Pragyan CMS12/2/201517/6/2026
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
ModificadaMedia (5)3.4%—Pragyan CMS Project Pragyan CMS12/1/201316/6/2026
Directory traversal vulnerability in download.lib.php in Pragyan CMS 3.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the fileget parameter in a profile action to index.php.
ModificadaAlta (7.5)0.99%—Pragyan CMS Project Pragyan CMS29/4/200916/6/2026
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.