Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.84% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Project Slims | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI. | |
| Modificada | Media (6.5) | 2.7% | — | Slims Akasia | 6/8/2017 | 17/6/2026 | SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users. | |
| Modificada | Alta (8.8) | 1.7% | — | Slims Akasia | 6/8/2017 | 17/6/2026 | SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users. | |
| Modificada | Alta (8.8) | 0.93% | — | Slims Senayan Library Management System | 6/8/2017 | 17/6/2026 | There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2… | |
| Modificada | Media (6.1) | 0.76% | — | Slims7 Cendana | 23/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php,… | |
| Modificada | Media (6.1) | 0.69% | — | Slims7 Cendana | 21/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php'… | |
| Modificada | Media (4.3) | 2.3% | — | Getusedtoit WP Slimstat | 21/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 2.0% | — | Getusedtoit WP Slimstat | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5.4) | 0.27% | — | Zillionmuslims Zillion Muslims | 21/10/2014 | 17/6/2026 | The Zillion Muslims (aka com.zillionmuslims.src) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Whitsoft Slimserve | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Whitsoft Slimserve | 3/5/2001 | 16/6/2026 | Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request. |