Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.69%—Itsourcecode Payroll SystemAI26/8/202628/8/2026
A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD Operation Handler. Executing a manipulation of the argument action can lead to missing authentication. The attack may be performed from remote. The exploit…
AplazadaMedia (5.5)0.50%—Itsourcecode Payroll SystemAI24/8/202624/8/2026
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
AplazadaMedia (5.5)0.43%—Itsourcecode Payroll SystemAI24/8/202626/8/2026
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
AplazadaBaja (2.1)0.20%—Codeastro Payroll SystemAI8/6/202623/7/2026
A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.
AplazadaBaja (2.1)0.21%—Codeastro Payroll SystemAI8/6/202623/7/2026
A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and…
AplazadaBaja (2.1)0.20%—Codeastro Payroll SystemAI1/6/202622/7/2026
A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.3)0.44%—Nurhodelta17 Attendance AND Payroll System27/10/202417/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Attendance and Payroll System 1.0. This issue affects some unknown processing of the file /admin/overtime_add.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.42%—Nurhodelta17 Attendance AND Payroll System27/10/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Attendance and Payroll System 1.0. This vulnerability affects unknown code of the file /admin/overtime_row.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.50%—Nurhodelta17 Attendance AND Payroll System27/10/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Attendance and Payroll System 1.0. This affects the function upload of the file /marimar/guest/update.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (6.1)0.60%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Online Payroll System 1.0. This issue affects some unknown processing of the file /admin/employee_edit.php. The manipulation of the argument of leads to cross site scripting. The attack may be initiated remotely. The exploit has…
ModificadaMedia (6.1)0.60%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Online Payroll System 1.0. This vulnerability affects unknown code of the file /admin/deduction_edit.php. The manipulation of the argument description leads to cross site scripting. The attack can be initiated remotely. The identifier of this…
ModificadaMedia (6.1)0.60%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability classified as problematic has been found in SourceCodester Online Payroll System 1.0. This affects an unknown part of the file /admin/employee_add.php. The manipulation of the argument of leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cashadvance_row.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability was found in SourceCodester Online Payroll System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/attendance_row.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability was found in SourceCodester Online Payroll System 1.0 and classified as critical. This issue affects some unknown processing of the file attendance.php. The manipulation of the argument employee leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability has been found in SourceCodester Online Payroll System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/deduction_row.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.81%—Online Payroll System Project Online Payroll System5/4/202317/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Online Payroll System 1.0. This affects an unknown part of the file /admin/employee_row.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (4.8)0.59%—Simple Payroll System With Dynamic TAX Bracket Project Simple Payroll System With Dynamic TAX Bracket1/3/202317/6/2026
A vulnerability was found in SourceCodester Simple Payroll System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file admin/?page=admin of the component POST Parameter Handler. The manipulation of the argument fullname leads to cross site scripting. The…
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php.
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php.
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.
ModificadaAlta (8.8)1.1%—Attendance AND Payroll System Project Attendance AND Payroll System21/4/202217/6/2026
Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.