Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.59% | — | Razormist Employee Management System | 29/1/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 1.0% | — | Employee Management System Project Employee Management System | 9/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Employee Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /process/aprocess.php. The manipulation of the argument mailuid leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.0% | — | Employee Management System Project Employee Management System | 9/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Employee Management System. It has been classified as critical. Affected is an unknown function of the file /process/eprocess.php. The manipulation of the argument mailuid/pwd leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 0.87% | — | Employee Management System Project Employee Management System | 9/8/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Employee Management System and classified as critical. This vulnerability affects unknown code of the file eloginwel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.61% | — | Razormist Employee Management System | 15/6/2021 | 17/6/2026 | A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account. | |
| Modificada | Media (5.4) | 0.54% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request. | |
| Modificada | Media (5.4) | 0.54% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request. | |
| Modificada | Media (5.4) | 0.54% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request. | |
| Modificada | Crítica (9.8) | 1.8% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System allows Arbitrary File Download via directory traversal sequences in the index.php form_file_name parameter in a download_form action. | |
| Modificada | Media (5.4) | 0.54% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request. | |
| Modificada | Alta (8.8) | 0.51% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action. | |
| Modificada | Media (5.4) | 0.54% | — | Iwcnetwork Biometric Shift Employee Management System | 30/12/2017 | 17/6/2026 | Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action. |