Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.65%—Projectworlds Leave Management System21/12/202317/6/2026
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaAlta (8.8)0.65%—Projectworlds Leave Management System21/12/202317/6/2026
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaMedia (5.3)0.76%—Jorani Leave Management System7/12/202317/6/2026
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
ModificadaAlta (8.8)0.65%—Projectworlds Leave Management System27/10/202317/6/2026
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
ModificadaMedia (6.5)0.52%💥 PoCJorani Leave Management System16/10/202317/6/2026
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of the List of Leave requests page.
ModificadaAlta (7.2)1.1%—Online Leave Management System Project Online Leave Management System7/12/202217/6/2026
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (4.8)0.45%—Online Leave Management System Project Online Leave Management System7/12/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /leave_system/admin/?page=maintenance/department. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted payload injected into the Name field under the…
ModificadaAlta (7.2)0.76%—Online Leave Management System Project Online Leave Management System17/11/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)1.3%—Online Leave Management System Project Online Leave Management System7/10/202217/6/2026
An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.2)1.0%—Online Leave Management System Project Online Leave Management System6/10/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department.
ModificadaAlta (7.2)0.97%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application.
ModificadaAlta (7.2)0.97%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.
ModificadaAlta (7.2)0.95%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.
ModificadaAlta (7.2)1.00%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.
ModificadaAlta (7.2)1.00%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php.
ModificadaAlta (7.2)0.98%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php.
ModificadaAlta (8.8)0.27%—Online Employee Leave Management System Project Online Employee Leave Management System5/9/202217/6/2026
A vulnerability was found in SourceCodester Online Employee Leave Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addemployee.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The…
ModificadaCrítica (9.8)1.4%—Online Leave Management System Project Online Leave Management System21/1/202217/6/2026
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
Orbitaley — Vulnerabilidades