Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Slimndap Theater FOR WordpressAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Alta (7.1) | 0.11% | — | Intel Slim BootloaderAI | 11/11/2025 | 17/6/2026 | Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Aplazada | Alta (7.6) | 0.36% | — | Senayan SlimsAI | 20/10/2025 | 17/6/2026 | An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter | |
| Aplazada | Media (6.5) | 0.31% | — | Slimndap Theater FOR WordpressAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress theatre allows Stored XSS.This issue affects Theater for WordPress: from n/a through <= 0.18.8. | |
| Aplazada | Alta (7.6) | 0.32% | — | Anhtransen Slim SEOAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anh Tran Slim SEO slim-seo allows SQL Injection.This issue affects Slim SEO: from n/a through <= 4.5.4. | |
| Aplazada | Media (6.4) | 0.51% | 💥 PoC | Slim SEOAI | 21/5/2025 | 17/6/2026 | The Slim SEO – Fast & Automated WordPress SEO Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slim_seo_breadcrumbs shortcode in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.16% | — | Intel Slim BootloaderAI | 13/5/2025 | 17/6/2026 | Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/bibliography/pop_author_edit.php. | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/author.php. | |
| Analizada | Media (6.5) | 0.32% | — | Slims Senayan Library Management System Bulian | 8/5/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian 9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/item_status.php. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Slims Senayan Library Management SystemAI | 29/4/2025 | 17/6/2026 | Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/coll_type.php. | |
| Aplazada | Media (4.3) | 0.40% | — | Slimndap Theater FOR WordpressAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Schmit Theater for WordPress theatre allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Theater for WordPress: from n/a through <= 0.18.7. | |
| Analizada | Alta (7.2) | 0.54% | — | Slims Senayan Library Management System | 24/2/2025 | 17/6/2026 | SQL injection in SLIMS v.9.6.1 allows a remote attacker to escalate privileges via the month parameter in the visitor_report_day.php component. | |
| Analizada | Media (6.7) | 0.63% | — | Slims Senayan Library Management System Bulian | 22/1/2025 | 17/6/2026 | A SQL Injection vulnerability exists in Senayan Library Management System SLiMS 9 Bulian 9.6.1 via the tempLoanID parameter in the loan form on /admin/modules/circulation/loan.php. | |
| Aplazada | Media (6.4) | 0.34% | — | Muslim Prayer Time Salah IqamahAI | 9/1/2025 | 17/6/2026 | The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (6.5) | 0.60% | — | Veronalabs Slimstat AnalyticsAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in VeronaLabs Slimstat Analytics wp-slimstat allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slimstat Analytics: from n/a through <= 5.0.5.1. | |
| Analizada | Media (6.1) | 0.60% | — | Slimndap Theater FOR Wordpress | 21/11/2024 | 17/6/2026 | The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.18.6.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 0.54% | — | Wp-slimstat Slimstat Analytics | 15/10/2024 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.5) | 0.47% | — | Automaticsystems SlimlaneAI | 14/10/2024 | 17/6/2026 | An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php component. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Automatic Systems Maintenance SlimlaneAI | 14/10/2024 | 17/6/2026 | Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page. | |
| Aplazada | Alta (8.8) | 0.47% | — | Automaticsystems SlimlaneAI | 14/10/2024 | 17/6/2026 | Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page. | |
| Aplazada | Media (6.1) | 0.32% | — | Automatic Systems Maintenance SlimlaneAI | 14/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component. | |
| Analizada | Media (6.1) | 0.36% | — | Slimselectjs Slim Select | 2/10/2024 | 14/7/2026 | Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is assigned to an innerHTML without sanitation. Software that depends on this library to dynamically generate lists using… | |
| Analizada | Alta (7.6) | 0.26% | — | Realwebcare Muslim Prayer Time BD | 26/6/2024 | 17/6/2026 | The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |
| Analizada | Media (4.9) | 0.55% | — | Slims Senayan Library Management System | 21/2/2024 | 17/6/2026 | SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php. |