Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.1%—Investintech Slimpdf Reader1/11/201116/6/2026
Investintech.com SlimPDF Reader does not prevent faulting-instruction data from affecting write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
ModificadaAlta (9.3)3.1%—Investintech Slimpdf Reader1/11/201116/6/2026
Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
ModificadaAlta (9.3)3.1%—Investintech Slimpdf Reader1/11/201116/6/2026
Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.
ModificadaMedia (6.9)0.30%—Simone Rota Slim Simple Login Manager30/8/201016/6/2026
The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.
ModificadaBaja (2.1)0.46%—Simone Rota Slim Simple Login Manager22/5/200916/6/2026
SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.
ModificadaAlta (7.5)2.6%💥 ExploitSlimcms24/12/200816/6/2026
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
ModificadaAlta (7.5)0.97%💥 ExploitSlimcms12/12/200816/6/2026
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.
ModificadaAlta (7.8)1.4%—Flashpeak Slim Browser9/2/200716/6/2026
Cross-domain vulnerability in Slim Browser 4.07 build 100 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes…
ModificadaMedia (5)7.2%💥 ExploitWhitsoft Development Slimftpd8/9/200516/6/2026
SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error.
ModificadaAlta (7.2)46%💥 ExploitWhitsoft Development Slimftpd26/7/200516/6/2026
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.
ModificadaAlta (7.2)1.4%💥 ExploitWhitsoft Development Slimftpd31/12/200416/6/2026
Buffer overflow in SlimFTPd 3.15 and earlier allows local users to execute arbitrary code via a long command, such as (1) CWD, (2) STOR, (3) MKD, and (4) STAT.
ModificadaMedia (5)1.4%—Whitsoft Development Slimftpd21/8/200116/6/2026
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.
ModificadaMedia (5)3.4%💥 ExploitWhitsoft Slimserve27/6/200116/6/2026
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.
ModificadaAlta (10)12%💥 ExploitWhitsoft Slimserve3/5/200116/6/2026
Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.
Orbitaley — Vulnerabilidades