Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.64% | — | Wp-slimstat Slimstat Analytics | 9/1/2023 | 17/6/2026 | The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs | |
| Modificada | Alta (7.5) | 0.79% | — | Slims Senayan Library Management System | 5/12/2022 | 17/6/2026 | SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter. | |
| Modificada | Alta (7.2) | 0.77% | — | Slims Senayan Library Management System | 1/11/2022 | 17/6/2026 | Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php. | |
| Modificada | Media (4.8) | 0.43% | — | Slims Senayan Library Management System | 1/11/2022 | 17/6/2026 | Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php. | |
| Modificada | Crítica (9.8) | 0.93% | — | Slims Senayan Library Management System | 12/9/2022 | 17/6/2026 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php. | |
| Modificada | Media (6.1) | 0.50% | — | Slims Senayan Library Management System | 12/9/2022 | 17/6/2026 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar. | |
| Modificada | Media (6.7) | 0.26% | — | Lenovo C340-14iml FirmwareLenovo C340-15iml FirmwareLenovo D330-10igm FirmwareLenovo Duet 3-10igl5 Firmware+58 | 22/4/2022 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (6.7) | 2.8% | 💥 PoC | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.2% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+69 | 22/4/2022 | 17/6/2026 | A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow an attacker with elevated privileges to modify firmware protection region by modifying an NVRAM variable. | |
| Modificada | Media (6.7) | 1.3% | — | Lenovo Ideapad 3-14ada05 FirmwareLenovo Ideapad 3-14ada6 FirmwareLenovo Ideapad 3-14alc6 FirmwareLenovo Ideapad 3-14are05 Firmware+101 | 22/4/2022 | 17/6/2026 | A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.1% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained. | |
| Modificada | Media (4.8) | 0.49% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php. | |
| Modificada | Alta (8.8) | 0.97% | — | Slims Senayan Library Management System | 17/3/2022 | 17/6/2026 | Slims8 Akasia 8.3.1 is affected by SQL injection in /admin/modules/bibliography/index.php, /admin/modules/membership/member_type.php, /admin/modules/system/user_group.php, and /admin/modules/membership/index.php through the dir parameter. It can be used by remotely authenticated librarian users. | |
| Modificada | Media (6.8) | 0.24% | — | Lenovo Ideapad 1-11ada05 FirmwareLenovo Ideapad 1-14ada05 FirmwareLenovo V130-15ikb FirmwareLenovo 100e 2ND GEN Firmware+17 | 16/7/2021 | 17/6/2026 | A vulnerability was reported on some Lenovo Notebook systems that could allow an attacker with physical access to elevate privileges under certain conditions during a BIOS update performed by Lenovo Vantage. | |
| Modificada | Media (4.6) | 0.24% | — | Lenovo Thinkpad Helix FirmwareLenovo Thinkpad T550 FirmwareLenovo Thinkpad W550s FirmwareLenovo Thinkpad X1 Carbon 3RD GEN Firmware+17 | 16/7/2021 | 17/6/2026 | Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage. | |
| Modificada | Media (4.6) | 0.52% | — | Protectimus Slim NFC 70 Firmware | 16/6/2021 | 17/6/2026 | Protectimus SLIM NFC 70 10.01 devices allow a Time Traveler attack in which attackers can predict TOTP passwords in certain situations. The time value used by the device can be set independently from the used seed value for generating time-based one-time passwords, without authentication. Thus, an attacker with… | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Alta (7.5) | 2.9% | — | Berlios SlimDebian Linux | 4/11/2019 | 16/6/2026 | slim has NULL pointer dereference when using crypt() method from glibc 2.17 | |
| Modificada | Media (6.1) | 1.0% | — | Wp-slimstat Slimstat Analytics | 21/8/2019 | 17/6/2026 | The wp-slimstat plugin before 4.8.1 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.3% | — | Wp-slimstat Slimstat Analytics | 7/10/2018 | 17/6/2026 | The wp-slimstat (aka Slimstat Analytics) plugin before 4.1.6.1 for WordPress has XSS via an HTTP Referer header, or via a field associated with JavaScript-based Referer tracking. | |
| Modificada | Alta (8.8) | 0.84% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Project Slims | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI. |