Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.26% | — | Projectworlds Expense Management System | 27/10/2025 | 17/6/2026 | A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Baja (1.9) | 0.26% | — | Projectworlds Expense Management System | 27/10/2025 | 17/6/2026 | A weakness has been identified in projectworlds Expense Management System 1.0. This impacts an unknown function of the file /public/admin/currencies/create of the component Currency Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available… | |
| Modificada | Baja (1.9) | 0.26% | — | Projectworlds Expense Management System | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in projectworlds Expense Management System 1.0. This affects an unknown function of the file /public/admin/roles/create of the component Roles Page. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public… | |
| Analizada | Baja (1.9) | 0.26% | — | Projectworlds Expense Management System | 27/10/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Expense Management System 1.0. The impacted element is an unknown function of the file /public/admin/users/create of the component Users Page. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Analizada | Baja (1.3) | 0.23% | — | Codeastro Expense Management System | 22/6/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Expense Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. | |
| Modificada | Media (6.1) | 0.43% | — | Oretnom23 Expense Management System | 30/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file templates/5-Add-Expenses.php of the component Add Expenses Page. The manipulation of the argument item leads to cross site scripting. The attack can be… | |
| Modificada | Alta (7.8) | 0.32% | — | Oretnom23 Expense Management System | 17/10/2023 | 17/6/2026 | An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component. | |
| Modificada | Media (5.4) | 0.70% | — | Oretnom23 Expense Management System | 28/9/2022 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php. | |
| Modificada | Alta (7.2) | 0.88% | — | Oretnom23 Expense Management System | 2/9/2022 | 17/6/2026 | Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p. | |
| Modificada | Crítica (9.8) | 0.55% | — | Expense Management System Project Expense Management System | 6/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be initiated… | |
| Modificada | Crítica (9.8) | 1.5% | — | Egavilanmedia Expense Management System | 2/6/2022 | 17/6/2026 | EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database. | |
| Modificada | Media (6.1) | 0.86% | — | Egavilanmedia Expense Management System | 15/12/2020 | 17/6/2026 | XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field |