Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.67% | — | Fabian Payroll Management System | 31/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_account.php. The manipulation of the argument salary_rate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.51% | — | Fabian Payroll Management System | 31/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. This affects an unknown part of the file update_account.php. The manipulation of the argument deduction leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.51% | — | Fabian Payroll Management System | 31/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /delete.php. The manipulation of the argument emp_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.53% | — | Fabian Payroll Management System | 27/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file update_employee.php. The manipulation of the argument emp_type leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.35% | — | Fabian Payroll Management System | 24/3/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.41% | — | Fabian Payroll Management System | 23/3/2025 | 17/6/2026 | A vulnerability was found in code-projects Payroll Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add_deductions.php. The manipulation of the argument bir leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.44% | — | Nurhodelta17 Attendance AND Payroll System | 27/10/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Attendance and Payroll System 1.0. This issue affects some unknown processing of the file /admin/overtime_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.42% | — | Nurhodelta17 Attendance AND Payroll System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Attendance and Payroll System 1.0. This vulnerability affects unknown code of the file /admin/overtime_row.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.50% | — | Nurhodelta17 Attendance AND Payroll System | 27/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the file /marimar/guest/update.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.76% | — | Razormist Payroll Management System | 25/10/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Payroll Management System 1.0. This affects the function login of the file main. The manipulation leads to buffer overflow. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.70% | — | Payroll Management System Project Payroll Management System | 8/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_deductions. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.61% | — | Kevinwong Payroll Management System | 22/8/2024 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.3) | 0.61% | — | Mdmafujulhasan Online-payroll-management-system | 26/7/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this issue is some unknown functionality of the file /employee_viewmore.php. The manipulation of the argument id leads to sql injection. The attack may be launched… | |
| Modificada | Media (5.3) | 0.54% | — | Mdmafujulhasan Online-payroll-management-system | 26/7/2024 | 17/6/2026 | A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file /department_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Media (5.3) | 0.59% | — | Mdmafujulhasan Online-payroll-management-system | 26/7/2024 | 17/6/2026 | A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected is an unknown function of the file /shift_viewmore.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Media (5.3) | 0.54% | — | Mdmafujulhasan Online-payroll-management-system | 26/7/2024 | 17/6/2026 | A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as critical. This issue affects some unknown processing of the file /branch_viewmore.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (5.3) | 0.54% | — | Mdmafujulhasan Online-payroll-management-system | 26/7/2024 | 17/6/2026 | A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as critical. This vulnerability affects unknown code of the file /designation_viewmore.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.67% | — | Itsourcecode Payroll Management System Project IN PHP With Source Code | 9/7/2024 | 17/6/2026 | SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Analizada | Crítica (9.8) | 2.0% | 💥 PoC | Oretnom23 Payroll Management System | 17/6/2024 | 17/6/2026 | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary… | |
| Modificada | Crítica (9.8) | 0.41% | — | Itsourcecode Payroll Management System | 14/6/2024 | 17/6/2026 | Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter. | |
| Modificada | Media (5.3) | 0.61% | — | Angeljudesuarez Payroll Management System | 12/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (6.5) | 0.45% | — | Aptos Wisal Payroll AccountingAI | 24/5/2024 | 17/6/2026 | Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list of usernames and passwords from the database server, using an unencrypted connection. This allows attackers in a machine-in-the-middle position read and write access to personally identifiable… | |
| Modificada | Media (6.1) | 0.45% | — | Oretnom23 Employees Payroll Management System | 1/5/2024 | 17/6/2026 | Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and to_date inputs in file Main.php. | |
| Modificada | Media (6.1) | 0.60% | — | Online Payroll System Project Online Payroll System | 5/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0. This issue affects some unknown processing of the file /admin/employee_edit.php. The manipulation of the argument of leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.60% | — | Online Payroll System Project Online Payroll System | 5/4/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affects unknown code of the file /admin/deduction_edit.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The identifier of this… |