Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.39% | — | Code-projects Employee Profile Management System | 9/12/2025 | 17/6/2026 | A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Carmelogarcia Employee Profile Management System | 8/12/2025 | 17/6/2026 | A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Modificada | Baja (2.1) | 0.38% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted upload. The attack may be launched remotely. The exploit has been released to the… | |
| Analizada | Baja (2) | 0.26% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A vulnerability was identified in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file /view_personnel.php. The manipulation of the argument per_address/dr_school/other_school leads to cross site scripting. The attack may be initiated remotely. The exploit is… | |
| Modificada | Baja (2.1) | 0.35% | — | Carmelogarcia Employee Profile Management System | 7/12/2025 | 17/6/2026 | A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the argument per_id can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and… | |
| Modificada | Media (6.1) | 0.43% | — | Carmelogarcia Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. The manipulation of the argument pos_name leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 0.60% | — | Code-projects Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.3) | 0.73% | — | Code-projects Employee Profile Management System | 12/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be… |