Project Contract Management
Vendor:
First CVE: Nov 25, 2025 · Active for under a year
7
Total CVEs
More Total CVEs than 85% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Project Contract Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 25, 2025
8 months ago
Most Recent CVE
Nov 25, 2025
245 days ago
CVE Severity & Scoring
Project Contract Management7 CVEs
29%
57%
14%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High0 (0.0%)
None3 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64063CRITICAL Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending dir | Nov 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-64065HIGH The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The administrative LoginAs or user impersonation feature is vul | Nov 25, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-64064HIGH Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH request to modify the PP_SECURITY_PROFILE_ID. Because of we | Nov 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-64066HIGH Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The endpoint fails to implement any authorization checks, allowing | Nov 25, 2025 | 8.6 | 27 | NO | NO |
CVE-2025-64062HIGH The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-side validation against the authenticated session. By manipula | Nov 25, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-64067MEDIUM Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles, project records) fail to implement sufficient server-side | Nov 25, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-64061MEDIUM Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access control mechanisms. Any authenticated user, regardless of their | Nov 25, 2025 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Project Contract Management
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0.18 | 7 | 7.8 | 0.3% | 0 | 0 |