Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Payroll Management System Project Payroll Management System5/4/202217/6/2026
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
ModificadaCrítica (9.8)3.0%—Attendance AND Payroll System Project Attendance AND Payroll System17/3/20229/7/2026
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
ModificadaCrítica (9.8)4.1%—Attendance AND Payroll System Project Attendance AND Payroll System17/3/20229/7/2026
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
ModificadaCrítica (9.8)2.8%—Simple Payroll System With Dynamic TAX Bracket Project Simple Payroll System With Dynamic TAX Bracket22/10/202117/6/2026
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no security and escaping from malicious…
ModificadaMedia (6.3)0.88%—Oracle Peoplesoft Enterprise Human Capital Management Global Payroll Core21/10/202017/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Core.…
ModificadaAlta (7.5)8.9%—Bouncycastle Bc-javaApache TomeeNetapp Active IQ Unified ManagerNetapp Oncommand API Services+178/10/201917/6/2026
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
ModificadaMedia (6.5)1.9%—Oracle Payroll24/4/201717/6/2026
Vulnerability in the Oracle Payables component of Oracle E-Business Suite (subcomponent: Self Service Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to…
ModificadaAlta (7.8)1.3%—SAP Payroll Process6/11/201417/6/2026
Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.
ModificadaAlta (7.5)1.3%—Enterprise Payroll Systems13/6/200616/6/2026
PHP remote file inclusion vulnerability in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in cal.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)3.6%💥 ExploitEnterprise Payroll Systems13/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in (1) footer.php and (2) admin/footer.php.
ModificadaBaja (2.1)0.21%—Kwik-pay Payroll7/3/200616/6/2026
Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, which allows local users to obtain sensitive information such as employment and payment data. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (10)9.6%—Checkmark PayrollCheckmark MultiledgerInnermedia Dynazip LibraryRealnetworks Realone Player+110/1/200516/6/2026
Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2)…
Orbitaley — Vulnerabilidades