Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.49% | — | Tildeslash M/monit | 28/1/2026 | 17/6/2026 | M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account. | |
| Analizada | Alta (7.1) | 0.49% | — | Tildeslash M/monit | 28/1/2026 | 17/6/2026 | M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users. | |
| Aplazada | Alta (7.1) | 0.18% | — | Giorgos Sarigiannidis Slash AdminAI | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Giorgos Sarigiannidis Slash Admin allows Cross-Site Scripting (XSS).This issue affects Slash Admin: from n/a through 3.8.1. | |
| Modificada | Alta (8.8) | 0.89% | — | Tildeslash Monit | 18/7/2023 | 17/6/2026 | An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization. | |
| Modificada | Media (6.1) | 1.1% | — | Trailing-slash Project Trailing-slash | 24/5/2021 | 17/6/2026 | The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of… | |
| Modificada | Media (5.4) | 0.83% | — | Koa-remove-trailing-slashes Project Koa-remove-trailing-slashes | 17/5/2021 | 17/6/2026 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative… | |
| Modificada | Media (6.1) | 0.53% | — | Google Slashify | 19/2/2021 | 17/6/2026 | The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring. | |
| Modificada | Alta (8.1) | 3.1% | — | Tildeslash MonitDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 22/4/2019 | 17/6/2026 | A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage). | |
| Modificada | Crítica (9.8) | 2.1% | — | Tildeslash Monit | 22/4/2019 | 17/6/2026 | An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Slashes&dots Offria | 8/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php. | |
| Modificada | Alta (10) | 49% | — | Phpslash | 11/2/2009 | 16/6/2026 | Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 1.8% | — | Slashcode.com Slash | 5/6/2008 | 16/6/2026 | SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Slashcode.com Slash | 5/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Derek Leung Pslash | 20/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in pSlash 0.70 allow remote attackers to execute arbitrary PHP code via a URL in (1) the lvc_admin_dir parameter to modules/visitors2/admin/view-archiver.inc.php or (2) the lvc_include_dir parameter to modules/visitors2/include/menus.inc.php. NOTE: the… | |
| Modificada | Alta (7.5) | 3.3% | — | Derek Leung Pslash | 26/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Mediaslash.com Mediaslash Gallery | 1/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable). | |
| Modificada | Alta (7.5) | 1.2% | — | Phpslash | 22/12/2005 | 16/6/2026 | SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter. | |
| Modificada | Alta (10) | 2.8% | — | Phpslash | 13/7/2005 | 16/6/2026 | The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Open Source Development Network Slashcode | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl. | |
| Modificada | Media (5) | 1.7% | — | Tildeslash Monit | 31/12/2004 | 16/6/2026 | The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes. | |
| Modificada | Alta (10) | 17% | — | Tildeslash Monit | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username. | |
| Modificada | Alta (10) | 21% | — | Tildeslash Monit | 31/12/2003 | 16/6/2026 | Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request. | |
| Modificada | Alta (7.2) | 0.36% | — | Freebsd Slashem-tty | 31/12/2003 | 16/6/2026 | slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris. | |
| Modificada | Media (5) | 3.7% | — | Tildeslash Monit | 24/11/2003 | 16/6/2026 | Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field. | |
| Modificada | Media (5) | 1.5% | — | Slashcode.com Slash | 31/12/2002 | 16/6/2026 | The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL. |