Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (0.9)0.17%—Proma-ai PromaAI10/9/202610/9/2026
A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulation of the argument file_path leads to path traversal. Local access is required to…
AplazadaAlta (7.1)0.24%—Promact WP Azure OffloadAI28/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0.
AplazadaMedia (5.1)0.53%—SEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI18/11/202417/6/2026
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
AplazadaAlta (7.1)0.66%—SEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI4/6/202417/6/2026
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
AplazadaAlta (8.7)3.7%—Microinvest Utnserver PROAIMicroinvest Utnserver PromaxAIMicroinvest Inu-100AI4/6/202417/6/2026
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-interface allows authenticated command injection.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
AplazadaAlta (8.3)5.5%—SEH Computertechnik Utnserver PROAISEH Computertechnik Utnserver PromaxAISEH Computertechnik Inu-100AI4/6/202417/6/2026
Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.
ModificadaAlta (7.8)0.35%—Dell Supportassist Client PromanageDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS12/3/202117/6/2026
Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially…
ModificadaMedia (4.3)1.6%—Itechscripts Proman Xpress13/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in client_details.php in Proman Xpress 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the cl_comments parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%—Itechscripts Proman Xpress13/8/201216/6/2026
SQL injection vulnerability in category_edit.php in Proman Xpress 5.0.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (6.8)4.1%—Giaard Proman2/6/201016/6/2026
Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2) managepmanagers.php, (3) manageusers.php, (4) helpfunc.php, (5) managegroups.php,…
ModificadaAlta (7.5)5.9%—Giaard Proman2/6/201016/6/2026
PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.
ModificadaAlta (7.5)2.5%—Promanager13/6/200816/6/2026
Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
ModificadaAlta (7.5)1.2%—Promanager28/8/200616/6/2026
SQL injection vulnerability in note.php in ProManager 0.73 allows remote attackers to execute arbitrary SQL commands via the note_id parameter.