Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

117 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.25%—Wedevs WP Project ManagerAI1/10/20261/10/2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
AplazadaBaja (2)0.15%—Devaslanphp Project ManagementAI28/9/20261/10/2026
A vulnerability has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. Affected is the function updateJiraProjects of the file /jira-import of the component Jira Import. The manipulation of the argument host/username/token leads to server-side request forgery. It is possible to initiate…
AplazadaBaja (2.1)0.19%—Devaslanphp Project ManagementAI28/9/202628/9/2026
A flaw has been found in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/v2.0.0-beta1. This impacts the function whereRaw of the file app/Filament/Widgets/Timesheet/MonthlyReport.php of the component Timesheet Dashboard. Executing a manipulation of the argument filter can lead to sql injection. The attack may…
AplazadaBaja (2.1)0.19%—Devaslanphp Project-managementAI28/9/202628/9/2026
A vulnerability was detected in DevaslanPHP project-management 1.2.1/1.2.2/1.2.3/1.2.4/2.0.0-beta1. This affects the function whereRaw of the file app/Filament/Widgets/Timesheet/ActivitiesReport.php of the component Timesheet Dashboard. Performing a manipulation of the argument filter results in sql injection. The…
AplazadaMedia (5.5)0.25%—Pmticket Project-management-softwareAI23/9/202624/9/2026
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates…
AplazadaMedia (6.4)0.33%—Zephyr Project ManagerAI8/9/20268/9/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to…
AplazadaMedia (4.3)0.27%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details…
AplazadaMedia (5.4)0.23%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.
AplazadaAlta (7.5)0.40%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
AplazadaMedia (4.8)0.36%💥 PoCEkushey Project Manager CRMAI25/8/202624/9/2026
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title element, and the text of an h4 element in the page header. The h4…
AplazadaMedia (6.5)0.38%—WP Project Manager PROAI25/8/202628/9/2026
El plugin WP Project Manager Pro para WordPress es vulnerable a inyección SQL en todas las versiones hasta, e incluyendo, la 4.0.1 debido a un escape insuficiente en el parámetro proporcionado por el usuario y la falta de preparación suficiente en la consulta SQL existente. Esto hace posible que atacantes…
AplazadaCrítica (9.8)0.56%—Wedevs WP Project ManagerAI24/8/202627/8/2026
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
AplazadaAlta (8.5)0.36%—WP Project Manager PROAI24/8/202624/8/2026
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
AplazadaMedia (5.1)0.29%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser…
AplazadaMedia (5.1)0.29%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts…
AplazadaMedia (5.1)0.29%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store…
AplazadaAlta (7.1)0.61%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting…
AplazadaCrítica (9.1)0.41%—Project Management BUG AND Issue Tracking PluginAI24/7/202624/7/2026
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin…
AnalizadaBaja (3.1)0.25%—Oracle Project Manufacturing21/7/202631/7/2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing. Successful…
AnalizadaBaja (3.6)0.11%—Oracle Project Manufacturing21/7/202631/7/2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to…
AnalizadaMedia (4.7)0.14%—Oracle Project Manufacturing21/7/202631/7/2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to…
AnalizadaMedia (5.7)0.14%—Oracle Project Manufacturing21/7/202631/7/2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to…
En análisisMedia (5.7)0.14%—Oracle Project Manufacturing21/7/202631/7/2026
Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to…
AplazadaBaja (2)0.35%—Code-projects Project Management SystemAI28/6/202630/6/2026
A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may…
AplazadaMedia (5.3)0.23%—Devaslansoftware Project-managementAI1/6/202622/7/2026
Una vulnerabilidad ha sido encontrada en la gestión de proyectos DevaslanPHP hasta la versión 2.0.0-beta1. Afectada por este problema es la función KanbanScrumHelper::recordUpdated del archivo app/Helpers/KanbanScrumHelper.php del componente Gestor de Tickets. La manipulación conduce a una autorización incorrecta. El…