Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.41%—Pkp.sfu Open Journal Systems1/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.
AnalizadaMedia (6.1)0.53%—Pkp.sfu Open Journal Systems1/3/202417/6/2026
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.
AnalizadaMedia (6.1)0.52%—Pkp.sfu Open Journal Systems1/3/202417/6/2026
Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.
ModificadaMedia (6.1)0.48%💥 PoCRemyandrade Travel Journal Using PHP AND Mysql With Source Code1/2/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.
ModificadaMedia (6.1)0.46%—Remyandrade Travel Journal Using PHP AND Mysql With Source Code1/2/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.
ModificadaAlta (7.5)0.28%—Aiven Journalpump21/12/202317/6/2026
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if…
ModificadaAlta (8.8)0.23%—Openjournalsystems Open Journal Systems11/12/202317/6/2026
A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
ModificadaMedia (5.4)0.40%—SFU Open Journal Systems1/11/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.
ModificadaAlta (8.8)0.26%—SFU Open Journal System18/10/202317/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.
ModificadaCrítica (9.8)0.52%—Turnatasarim Advertising Administration Panel6/10/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1.
ModificadaMedia (6.5)1.2%—Tildearrow Furnace10/4/202217/6/2026
A denial of service vulnerability was found in tildearrow Furnace. It has been classified as problematic. This is due to an incomplete fix of CVE-2022-1211. It is possible to initiate the attack remotely but it requires user interaction. The issue got fixed with the patch 0eb02422d5161767e9983bdaa5c429762d3477ce.
ModificadaMedia (6.1)1.0%—Public Knowledge Project Open Journal Systems4/4/202217/6/2026
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
ModificadaMedia (6.5)0.91%—Tildearrow Furnace3/4/202217/6/2026
A vulnerability classified as critical has been found in tildearrow Furnace dev73. This affects the FUR to VGM converter in console mode which causes stack-based overflows and crashes. It is possible to initiate the attack remotely but it requires user-interaction. A POC has been disclosed to the public and may be…
ModificadaMedia (6.1)6.1%💥 ExploitPublic Knowledge Project Open Journal Systems1/4/202217/6/2026
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
ModificadaMedia (5.4)0.55%—Accounting Journal Management Project Accounting Journal Management24/2/202217/6/2026
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
ModificadaAlta (7.5)4.7%💥 ExploitJournal-theme Journal1/7/202017/6/2026
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
ModificadaAlta (8.8)1.4%—SFU Open Journal System19/12/201917/6/2026
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
ModificadaMedia (6.1)1.8%—SFU Open Journal System12/6/201817/6/2026
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field).
ModificadaMedia (5.9)0.95%—Gurunavi Gournavi10/10/201717/6/2026
Gurunavi App for iOS before 6.0.0 does not verify SSL certificates which could allow remote attackers to perform man-in-the-middle attacks.
ModificadaCrítica (9.8)1.8%—BD PerformaBD KLA Journal Service30/6/201717/6/2026
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of…
ModificadaMedia (4.3)1.2%—Tournament Project Tournament6/7/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, or a (3) team entity title.
ModificadaMedia (5.4)0.27%—Bloodjournal Blood20/10/201417/6/2026
The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Gannett Lansing State Journal Print19/10/201417/6/2026
The Lansing State Journal Print (aka com.lansingjournal.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Pocketmags NRA Journal19/10/201417/6/2026
The NRA Journal (aka com.magazinecloner.nationalrifleassociationjournal) application @7F080181 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Somcloud Somnote - Journal/memo9/9/201417/6/2026
The SomNote - Journal/Memo (aka com.somcloud.somnote) application 2.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades