Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM Approve Timesheets FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Baja (3.1) | 0.21% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability… | |
| Aplazada | Media (6.5) | 0.24% | — | SAP HCM MY Timesheet FioriAI | 9/9/2025 | 17/6/2026 | SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected. | |
| Aplazada | Media (4.3) | 0.26% | — | SAP HCM Approve TimesheetsAI | 10/12/2024 | 17/6/2026 | SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted. | |
| Analizada | Media (5.3) | 0.44% | — | Rems Online Timesheet APP | 29/9/2024 | 17/6/2026 | A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting. The attack can be… | |
| Analizada | Media (5.3) | 0.53% | — | Rems Online Timesheet APP | 29/9/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.63% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 30/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_company. The manipulation of the argument name with the input… | |
| Modificada | Crítica (9.8) | 0.78% | — | Students Online Internship Timesheet System Project Students Online Internship Timesheet System | 29/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch… | |
| Modificada | Media (5.4) | 0.44% | — | Timesheets-for-jira Timesheet Tracking | 17/4/2023 | 17/6/2026 | The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view. | |
| Modificada | Media (6.5) | 0.30% | — | Dolibarr Project Timesheet Project Dolibarr Project Timesheet | 27/12/2022 | 17/6/2026 | A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address… | |
| Modificada | Media (6.1) | 1.4% | — | Bestwebsoft Timesheet | 27/8/2019 | 17/6/2026 | The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues. | |
| Modificada | Media (6.1) | 4.3% | — | Timesheet Next GEN Project Timesheet Next GEN | 17/7/2019 | 17/6/2026 | Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious… | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Alta (7.5) | 1.9% | — | Peter Kovacs Timesheet Next GEN | 19/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Truworthit Flex Timesheet | 27/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |
| Modificada | Media (4.3) | 0.83% | — | Pacifictimesheet Pacific Timesheet | 28/5/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action. | |
| Modificada | Media (5) | 2.7% | — | Ultrize Timesheet | 10/9/2009 | 16/6/2026 | Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter. | |
| Modificada | Media (6.8) | 1.7% | — | Ultrize Timesheet | 14/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter. | |
| Modificada | Media (5) | 1.2% | — | Dominic Gamble Timesheet.php | 12/9/2006 | 16/6/2026 | SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Carey Briggs PHP Mysql Timesheet | 15/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. |