Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▼ 116 respecto a la semana anterior
Críticas / altas1419▲ 175 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.4) | 0.24% | — | Konsola ProgetAI | 21/5/2025 | 17/6/2026 | Data provided in a request performed to the server while activating a new device are put in a database. Other high privileged users might download this data as a CSV file and corrupt their PC by opening it in a tool such as Microsoft Excel. The attacker could gain remote access to the user's PC. This issue has been… | |
| Aplazada | Baja (2.4) | 0.23% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | Input provided in a field containing "activationMessage" in Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite). | |
| Aplazada | Baja (2.4) | 0.23% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | Input provided in comment section of Konsola Proget is not sanitized correctly, allowing a high-privileged user to perform a Stored Cross-Site Scripting attack. This issue has been fixed in 2.17.5 version of Konsola Proget (server part of the MDM suite). | |
| Aplazada | Media (5.1) | 0.18% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | A low-privileged user can access information about profiles created in Proget MDM (Mobile Device Management), which contain details about allowed/prohibited functions. The profiles do not reveal any sensitive information (including their usage in connected devices). This issue has been fixed in 2.17.5 version of… | |
| Aplazada | Media (4.6) | 0.18% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | In Proget MDM, a low-privileged user can access information about changes contained in backups of all devices managed by the MDM (Mobile Device Management). This information include user ids, email addresses, first names, last names and device UUIDs. The last one can be used for exploitation of CVE-2025-1416.… | |
| Aplazada | Alta (7) | 0.19% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | In Proget MDM, a low-privileged user can retrieve passwords for managed devices and subsequently use functionalities restricted by the MDM (Mobile Device Management). For it to happen, they must know the UUIDs of targetted devices, which might be obtained by exploiting CVE-2025-1415 or CVE-2025-1417. This issue has… | |
| Aplazada | Media (5.1) | 0.21% | — | Inedo ProgetAI | 21/5/2025 | 17/6/2026 | A low-privileged user is able to obtain information about tasks executed on devices controlled by Proget MDM (Mobile Device Management), as well as details of the devices like their UUIDs needed for exploitation of CVE-2025-1416. In order to perform the attack, one has to know a task_id, but since it's a low integer… | |
| Aplazada | Alta (7.3) | 0.47% | — | Inedo ProgetAI | 3/5/2025 | 17/6/2026 | Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is… | |
| Modificada | Crítica (9.8) | 0.66% | — | Progetto-complementi Project Progetto-complementi | 5/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in Miccighel PR-CWT. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as e412127d07004668e5a213932c94807d87067a1f. It is recommended to apply a patch to fix this issue. VDB-217486 is the identifier assigned to… | |
| Modificada | Alta (7.5) | 0.89% | — | Jenkins Inedo Proget | 25/9/2019 | 17/6/2026 | Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (6.5) | 0.41% | — | Inedo Proget | 26/9/2018 | 17/6/2026 | Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings. | |
| Modificada | Alta (7.4) | 0.79% | — | Jenkins Inedo Proget | 1/8/2018 | 17/6/2026 | A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to. | |
| Modificada | Alta (7.5) | 0.86% | — | Inedo Proget | 30/9/2017 | 17/6/2026 | Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060. |