Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.24%—SAP HCM Approve Timesheets FioriAI9/9/202517/6/2026
SAP HCM Approve Timesheets Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.
AplazadaBaja (3.1)0.21%—SAP HCM MY Timesheet FioriAI9/9/202517/6/2026
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability…
AplazadaBaja (3.1)0.21%—SAP HCM MY Timesheet FioriAI9/9/202517/6/2026
Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability…
AplazadaMedia (6.5)0.24%—SAP HCM MY Timesheet FioriAI9/9/202517/6/2026
SAP HCM My Timesheet Fiori 2.0 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This issue has a significant impact on the application's integrity, while confidentiality and availability remain unaffected.
AplazadaMedia (4.3)0.26%—SAP HCM Approve TimesheetsAI10/12/202417/6/2026
SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.
AnalizadaMedia (5.3)0.44%—Rems Online Timesheet APP29/9/202417/6/2026
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross site scripting. The attack can be…
AnalizadaMedia (5.3)0.53%—Rems Online Timesheet APP29/9/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (6.1)0.63%—Students Online Internship Timesheet System Project Students Online Internship Timesheet System30/5/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Students Online Internship Timesheet Syste 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_company. The manipulation of the argument name with the input…
ModificadaCrítica (9.8)0.78%—Students Online Internship Timesheet System Project Students Online Internship Timesheet System29/5/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch…
ModificadaMedia (5.4)0.44%—Timesheets-for-jira Timesheet Tracking17/4/202317/6/2026
The TouchDown Timesheet tracking component 4.1.4 for Jira allows XSS in the calendar view.
ModificadaMedia (6.5)0.30%—Dolibarr Project Timesheet Project Dolibarr Project Timesheet27/12/202217/6/2026
A vulnerability was found in dolibarr_project_timesheet up to 4.5.5. It has been declared as problematic. This vulnerability affects unknown code of the component Form Handler. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. Upgrading to version 4.5.6.a is able to address…
ModificadaMedia (6.1)1.4%—Bestwebsoft Timesheet27/8/201917/6/2026
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
ModificadaMedia (6.1)4.3%—Timesheet Next GEN Project Timesheet Next GEN17/7/201917/6/2026
Timesheet Next Gen 1.5.3 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Allows an attacker to execute arbitrary HTML and JavaScript code via a "redirect" parameter. The component is: Web login form: login.php, lines 40 and 54. The attack vector is: reflected XSS, victim may click the malicious…
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaAlta (7.5)1.9%—Peter Kovacs Timesheet Next GEN19/9/201216/6/2026
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaAlta (7.5)1.2%—Truworthit Flex Timesheet27/4/201116/6/2026
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
ModificadaMedia (4.3)0.83%—Pacifictimesheet Pacific Timesheet28/5/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.
ModificadaMedia (5)2.7%—Ultrize Timesheet10/9/200916/6/2026
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.
ModificadaMedia (6.8)1.7%—Ultrize Timesheet14/8/200916/6/2026
PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.
ModificadaMedia (5)1.2%—Dominic Gamble Timesheet.php12/9/200616/6/2026
SQL injection vulnerability in login.php in dwayner79 and Dominic Gamble Timesheet (aka Timesheet.php) 1.2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)1.4%—Carey Briggs PHP Mysql Timesheet15/2/200616/6/2026
Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php.