Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.49%—Tildeslash M/monit28/1/202617/6/2026
M/Monit 3.7.4 contains a privilege escalation vulnerability that allows authenticated users to modify user permissions by manipulating the admin parameter. Attackers can send a POST request to the /api/1/admin/users/update endpoint with a crafted payload to grant administrative access to a standard user account.
AnalizadaAlta (7.1)0.49%—Tildeslash M/monit28/1/202617/6/2026
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users.
AplazadaAlta (7.1)0.18%—Giorgos Sarigiannidis Slash AdminAI24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Giorgos Sarigiannidis Slash Admin allows Cross-Site Scripting (XSS).This issue affects Slash Admin: from n/a through 3.8.1.
ModificadaAlta (8.8)0.89%—Tildeslash Monit18/7/202317/6/2026
An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.
ModificadaMedia (6.1)1.1%—Trailing-slash Project Trailing-slash24/5/202117/6/2026
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of…
ModificadaMedia (5.4)0.83%—Koa-remove-trailing-slashes Project Koa-remove-trailing-slashes17/5/202117/6/2026
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative…
ModificadaMedia (6.1)0.53%—Google Slashify19/2/202117/6/2026
The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.
ModificadaAlta (8.1)3.1%—Tildeslash MonitDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux22/4/201917/6/2026
A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).
ModificadaCrítica (9.8)2.1%—Tildeslash Monit22/4/201917/6/2026
An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their privileges to an administrator by requesting a password change and specifying the admin parameter.
ModificadaMedia (4.3)1.2%—Slashes&dots Offria8/5/201417/6/2026
Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.
ModificadaAlta (10)49%—Phpslash11/2/200916/6/2026
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)1.8%—Slashcode.com Slash5/6/200816/6/2026
SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.
ModificadaMedia (4.3)1.6%—Slashcode.com Slash5/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.
ModificadaAlta (7.5)1.5%—Derek Leung Pslash20/9/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in pSlash 0.70 allow remote attackers to execute arbitrary PHP code via a URL in (1) the lvc_admin_dir parameter to modules/visitors2/admin/view-archiver.inc.php or (2) the lvc_include_dir parameter to modules/visitors2/include/menus.inc.php. NOTE: the…
ModificadaAlta (7.5)3.3%—Derek Leung Pslash26/8/200616/6/2026
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.
ModificadaAlta (7.5)3.2%—Mediaslash.com Mediaslash Gallery1/4/200616/6/2026
PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).
ModificadaAlta (7.5)1.2%—Phpslash22/12/200516/6/2026
SQL injection vulnerability in article.php in phpSlash 0.8.1 and earlier allows remote attackers to execute arbitrary SQL commands via the story_id parameter.
ModificadaAlta (10)2.8%—Phpslash13/7/200516/6/2026
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.
ModificadaMedia (4.3)1.4%—Open Source Development Network Slashcode31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.
ModificadaMedia (5)1.7%—Tildeslash Monit31/12/200416/6/2026
The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.
ModificadaAlta (10)17%—Tildeslash Monit31/12/200416/6/2026
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
ModificadaAlta (10)21%—Tildeslash Monit31/12/200316/6/2026
Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.
ModificadaAlta (7.2)0.36%—Freebsd Slashem-tty31/12/200316/6/2026
slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary code as other users, as demonstrated using a separate vulnerability in LTris.
ModificadaMedia (5)3.7%—Tildeslash Monit24/11/200316/6/2026
Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.
ModificadaMedia (5)1.5%—Slashcode.com Slash31/12/200216/6/2026
The quick login feature in Slash Slashcode does not redirect the user to an alternate URL when the wrong password is provided, which makes it easier for remote web sites to guess the proper passwords by reading the username and password from the Referrer URL.