Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242. | |
| Modificada | Media (6.1) | 0.86% | — | Slims Akasia Project Slims Akasia | 22/6/2018 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI. | |
| Modificada | Alta (8.1) | 1.8% | — | Slimerjs-edge Project Slimerjs-edge | 4/6/2018 | 17/6/2026 | slimerjs-edge is a npm wrapper for installing the bleeding edge version of slimerjs. slimerjs-edge downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the… | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter. | |
| Modificada | Alta (7.2) | 1.1% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script allows arbitrary file upload via admin/mydetails_edit.php. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter. | |
| Modificada | Media (4.8) | 0.50% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter. | |
| Modificada | Alta (8.8) | 0.94% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has SQL injection via the view-profile.php mem_id parameter. | |
| Modificada | Media (6.8) | 0.40% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php. | |
| Modificada | Media (5.4) | 0.49% | — | Muslim Matrimonial Script Project Muslim Matrimonial Script | 30/12/2017 | 17/6/2026 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Muslim Matrimonial Script Project Muslim Matrimonial Script | 13/12/2017 | 17/6/2026 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | |
| Modificada | Media (6.5) | 2.7% | — | Slims Akasia | 6/8/2017 | 17/6/2026 | SLiMS 8 Akasia through 8.3.1 has an arbitrary file reading issue because of directory traversal in the url parameter to admin/help.php. It can be exploited by remote authenticated librarian users. | |
| Modificada | Alta (8.8) | 1.7% | — | Slims Akasia | 6/8/2017 | 17/6/2026 | SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users. | |
| Modificada | Alta (8.8) | 0.93% | — | Slims Senayan Library Management System | 6/8/2017 | 17/6/2026 | There is no CSRF mitigation in SLiMS 8 Akasia through 8.3.1. Also, an entire user profile (including the password) can be updated without sending the current password. This allows remote attackers to trick a user into changing to an attacker-controlled password, a complete account takeover, via the passwd1 and passwd2… | |
| Modificada | Media (6.1) | 0.76% | — | Slims7 Cendana | 23/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php,… | |
| Modificada | Media (6.1) | 0.69% | — | Slims7 Cendana | 21/3/2017 | 17/6/2026 | Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7_cendana-master/template/default/detail_template.php' and 'slims7_cendana-master/template/default-rtl/detail_template.php'… | |
| Modificada | Alta (7.8) | 0.35% | — | Lenovo Edge Keyboard DriverLenovo Slim USB Keyboard Driver | 26/1/2017 | 17/6/2026 | Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges. | |
| Modificada | Media (6.5) | 1.0% | — | Amazonbasics FirmwareDell Km714 FirmwareDell Km632 FirmwareLogitech Unifying Firmware+1 | 2/8/2016 | 17/6/2026 | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity… | |
| Modificada | Alta (7.5) | 2.5% | — | Slimframework Slim | 30/3/2015 | 17/6/2026 | Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data. | |
| Modificada | Media (4.3) | 2.3% | — | Getusedtoit WP Slimstat | 21/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Save Filters functionality in the WP Slimstat plugin before 3.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fs[resource] parameter in the wp-slim-view-2 page to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 2.0% | — | Getusedtoit WP Slimstat | 13/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WP SlimStat plugin before 3.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5.4) | 0.27% | — | Zillionmuslims Zillion Muslims | 21/10/2014 | 17/6/2026 | The Zillion Muslims (aka com.zillionmuslims.src) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 7.4% | 💥 Exploit | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Alta (9.3) | 3.1% | — | Investintech Slimpdf Reader | 1/11/2011 | 16/6/2026 | Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. |