Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.45% | — | Wp-slimstat Slimstat Analytics | 2/2/2024 | 17/6/2026 | The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Alta (8.8) | 0.75% | — | Slims Senayan Library Management System Bulian | 1/12/2023 | 17/6/2026 | SLiMS (aka SENAYAN Library Management System) through 9.6.1 allows admin/modules/reporting/customs/staff_act.php SQL Injection via startDate or untilDate. | |
| Modificada | Alta (8.8) | 0.75% | — | Slims Senayan Library Management System Bulian | 1/12/2023 | 17/6/2026 | Senayan Library Management Systems (Slims) 9 Bulian v9.6.1 is vulnerable to SQL Injection via admin/modules/reporting/customs/fines_report.php. | |
| Modificada | Media (4.8) | 0.39% | — | Slimndap Theater FOR Wordpress | 23/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Schmit Theater for WordPress plugin <= 0.18.3 versions. | |
| Modificada | Crítica (9.8) | 0.51% | — | Wp-slimstat Slimstat Analytics | 6/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics allows SQL Injection.This issue affects Slimstat Analytics: from n/a through 5.0.4. | |
| Modificada | Alta (8.8) | 1.1% | — | Slims Senayan Library Management SystemSlims Senayan Library Management System Bulian | 31/10/2023 | 17/6/2026 | SQL injection vulnerability in Senayan Library Management Systems Slims v.9 and Bulian v.9.6.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the reborrowLimit parameter in the member_type.php. | |
| Modificada | Media (6.5) | 1.1% | — | Wp-slimstat Slimstat Analytics | 20/10/2023 | 17/6/2026 | The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Ideapad Creator 5-16ach6 FirmwareLenovo Ideapad 5 Pro-16ihu6 FirmwareLenovo Ideapad 5 Pro-16ach6 FirmwareLenovo Yoga Slim 7-13itl05 Firmware+21 | 9/10/2023 | 17/6/2026 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Alta (8.8) | 0.56% | — | Slims Senayan Library Management System | 2/10/2023 | 17/6/2026 | Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter. | |
| Modificada | Media (4.8) | 0.42% | — | Wp-slimstat Slimstat Analytics | 27/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.8 versions. | |
| Modificada | Alta (8.8) | 0.74% | — | Slims Senayan Library Management System | 1/9/2023 | 17/6/2026 | Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | |
| Modificada | Media (6.1) | 0.39% | — | Slims Senayan Library Management System | 1/9/2023 | 17/6/2026 | Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php. | |
| Modificada | Media (5.4) | 0.67% | — | Wp-slimstat Slimstat Analytics | 30/8/2023 | 17/6/2026 | The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slimstat' shortcode in versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. | |
| Modificada | Media (6.7) | 0.17% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. | |
| Modificada | Media (4.4) | 0.18% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. | |
| Modificada | Media (6.7) | 0.19% | — | Lenovo Ideapad 1 14iau7 FirmwareLenovo Ideapad 1 14igl7 FirmwareLenovo Ideapad 1 15iau7 FirmwareLenovo Ideapad 1 15igl7 Firmware+83 | 23/8/2023 | 17/6/2026 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. | |
| Modificada | Media (6.1) | 0.41% | — | Wp-slimstat Slimstat Analytics | 25/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <= 5.0.4 versions. | |
| Modificada | Media (6.5) | 0.74% | — | Slimframework Slim Psr-7 | 17/4/2023 | 17/6/2026 | slim/psr7 is a PSR-7 implementation for use with Slim 4. In versions prior to 1.6.1 an attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. An attacker that is… | |
| Modificada | Alta (7.5) | 0.75% | — | Slims Senayan Library Management System | 14/4/2023 | 17/6/2026 | SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation and device information. | |
| Modificada | Alta (8.8) | 5.1% | 💥 Exploit | Wp-slimstat Slimstat Analytics | 20/3/2023 | 17/6/2026 | The Slimstat Analytics WordPress plugin before 4.9.3.3 does not prevent subscribers from rendering shortcodes that concatenates attributes directly into an SQL query. | |
| Modificada | Media (6.1) | 0.47% | — | Slims Project Slims | 13/2/2023 | 17/6/2026 | SLIMS v9.5.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /customs/loan_by_class.php?reportView. | |
| Modificada | Alta (7.8) | 0.34% | — | Lenovo 100e 2ND GEN FirmwareLenovo 100w GEN 3 FirmwareLenovo 13W Yoga FirmwareLenovo 14W GEN 2 Firmware+66 | 26/1/2023 | 17/6/2026 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo D330-10igl FirmwareLenovo Ideapad 5 PRO 16iah7 FirmwareLenovo Ideapad 5 PRO 16arh7 FirmwareLenovo Ideapad Duet 3 10igl5 Firmware+40 | 23/1/2023 | 17/6/2026 | A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. |