Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.20% | — | Codeastro Payroll SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |
| Aplazada | Media (4.7) | 0.27% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |
| Aplazada | Baja (2.1) | 0.45% | — | Itsourcecode Payroll Management SystemAI | 2/4/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation of the argument page leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Payroll Management SystemAI | 1/4/2026 | 17/6/2026 | A weakness has been identified in itsourcecode Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /view_employee.php of the component Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Itsourcecode Payroll Management SystemAI | 31/3/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /manage_user.php of the component Parameter Handler. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out… | |
| Aplazada | Baja (2.1) | 0.45% | — | Itsourcecode Payroll Management SystemAI | 26/3/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode Payroll Management System up to 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public… | |
| Analizada | Media (5.5) | 0.58% | — | Angeljudesuarez Payroll Management System | 16/3/2026 | 17/6/2026 | A vulnerability was identified in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /manage_employee.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.45% | — | Itsourcecode Payroll Management SystemAI | 12/3/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unknown code of the file /manage_employee_deductions.php. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 0.48% | — | Angeljudesuarez Payroll Management System | 9/3/2026 | 17/6/2026 | A vulnerability was determined in itsourcecode Payroll Management System 1.0. Affected is an unknown function of the file /manage_employee_allowances.php. This manipulation of the argument ID causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may… | |
| Aplazada | Media (5.3) | 1.9% | — | Times Software E-payrollAI | 18/11/2025 | 17/6/2026 | Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not sanitized properly, which allows an unauthenticated attacker to perform DoS attacks. SQL injection attacks might also be feasible, although so far creating a working exploit has been prevented probably by… | |
| Analizada | Media (5.5) | 0.53% | — | Campcodes Payroll Management System | 27/8/2025 | 17/6/2026 | A weakness has been identified in Campcodes Payroll Management System 1.0. The affected element is the function include of the file /index.php. This manipulation of the argument page causes file inclusion. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be… | |
| Analizada | Alta (8.1) | 0.29% | — | Oracle Peoplesoft Enterprise HCM Global Payroll Core | 15/7/2025 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.51 and 9.2.52. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft… | |
| Analizada | Media (5.5) | 0.44% | — | Campcodes Payroll Management System | 9/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_deductions. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.5) | 0.44% | — | Campcodes Payroll Management System | 9/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_allowances. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.44% | — | Campcodes Payroll Management System | 9/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_position. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.44% | — | Campcodes Payroll Management System | 9/7/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=save_position. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.5) | 0.52% | — | Campcodes Payroll Management System | 7/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_payroll. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.52% | — | Campcodes Payroll Management System | 7/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=save_employee_attendance. The manipulation of the argument employee_id leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.5) | 0.52% | — | Campcodes Payroll Management System | 7/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /ajax.php?action=delete_payroll. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.52% | — | Campcodes Payroll Management System | 7/7/2025 | 17/6/2026 | A vulnerability was found in Campcodes Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=delete_employee_attendance_single. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.52% | — | Campcodes Payroll Management System | 7/7/2025 | 17/6/2026 | A vulnerability has been found in Campcodes Payroll Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=calculate_payroll. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.49% | — | Campcodes Payroll Management System | 28/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /Payroll_Management_System/ajax.php?action=save_department. The manipulation of the argument ID leads to sql injection. The attack may be… | |
| Analizada | Media (5.3) | 0.53% | — | Fabian Payroll Management System | 3/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.67% | — | Fabian Payroll Management System | 31/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_employee.php. The manipulation of the argument lname/fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… |