Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2553▼ 349 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.18% | — | HrsaleAI | 5/2/2026 | 17/6/2026 | HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated… | |
| Modificada | Media (6.1) | 0.70% | — | Hrsale | 24/11/2020 | 17/6/2026 | HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter. | |
| Modificada | Media (5.3) | 2.5% | — | Hrsale | 29/10/2020 | 17/6/2026 | Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files. | |
| Modificada | Alta (8.8) | 5.6% | — | Hrsale Project Hrsale | 1/5/2018 | 17/6/2026 | A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | |
| Modificada | Media (5.4) | 1.6% | — | Hrsale Project Hrsale | 1/5/2018 | 17/6/2026 | An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user. | |
| Modificada | Alta (8.8) | 4.2% | — | Hrsale Project Hrsale | 1/5/2018 | 17/6/2026 | A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution. | |
| Modificada | Alta (8.8) | 2.5% | — | Hrsale Project Hrsale | 1/5/2018 | 17/6/2026 | A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query. |