Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.21%—Sourcecodester Online Leave Management SystemAI30/9/202630/9/2026
A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available…
AplazadaBaja (2.1)0.33%—Codeastro Simple Online Leave Management SystemAI13/7/202613/7/2026
A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.…
AplazadaBaja (2.1)0.33%—Codeastro Simple Online Leave Management SystemAI13/7/202613/7/2026
A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has…
AplazadaBaja (2.1)0.33%—Coderastro Simple Online Leave Management SystemAI13/7/202614/7/2026
A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be initiated remotely. The exploit has been made…
AplazadaMedia (5.5)0.43%—Codeastro Simple Online Leave Management SystemAI9/7/20269/7/2026
A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has…
ModificadaAlta (7.2)1.1%—Online Leave Management System Project Online Leave Management System7/12/202217/6/2026
Online Leave Management System v1.0 was discovered to contain an arbitrary file upload vulnerability at /leave_system/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (4.8)0.45%—Online Leave Management System Project Online Leave Management System7/12/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /leave_system/admin/?page=maintenance/department. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted payload injected into the Name field under the…
ModificadaAlta (7.2)0.76%—Online Leave Management System Project Online Leave Management System17/11/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.
ModificadaAlta (7.2)1.3%—Online Leave Management System Project Online Leave Management System7/10/202217/6/2026
An arbitrary file upload vulnerability in the component /leave_system/classes/Users.php?f=save of Online Leave Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.2)1.0%—Online Leave Management System Project Online Leave Management System6/10/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /leave_system/classes/Master.php?f=delete_department.
ModificadaAlta (7.2)0.97%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application.
ModificadaAlta (7.2)0.97%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_designation.
ModificadaAlta (7.2)0.95%—Online Leave Management System Project Online Leave Management System26/9/202217/6/2026
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_leave_type.
ModificadaAlta (7.2)1.00%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_leave_type.php.
ModificadaAlta (7.2)1.00%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /employees/manage_leave_type.php.
ModificadaAlta (7.2)0.98%—Online Leave Management System Project Online Leave Management System12/9/202217/6/2026
Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /maintenance/manage_department.php.
ModificadaCrítica (9.8)1.4%—Online Leave Management System Project Online Leave Management System21/1/202217/6/2026
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
Orbitaley — Vulnerabilidades