Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.3% | 💥 Exploit | Public Knowledge Project Open Journal Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | PKP Open Journal Systems | 6/9/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser… | |
| Modificada | Media (6) | 3.5% | 💥 Exploit | PKP Open Journal Systems | 6/9/2012 | 16/6/2026 | Incomplete blacklist vulnerability in Open Journal Systems before 2.3.7 allows remote authenticated users with the Author Role permission to execute arbitrary code by uploading a file with an executable extension that is not ".php", then accessing it via a direct request to the file in submission/original/ in the… | |
| Modificada | Media (6.5) | 3.0% | 💥 Exploit | PKP Open Journal Systems | 6/9/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in the iBrowser plugin library, as used in Open Journal Systems before 2.3.7, allow remote authenticated users to (1) delete or (2) rename arbitrary files via a .. (dot dot) in the param parameter to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/scripts/rfiles.php. | |
| Modificada | Alta (9.3) | 4.9% | — | Epicgames Unreal EngineEpicgames Postal 2Epicgames Raven ShieldEpicgames Swat 4+2 | 12/7/2010 | 16/6/2026 | Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, allows remote attackers to execute arbitrary code via a long LEVEL… | |
| Modificada | Baja (2.1) | 0.35% | — | Becauseinter Bournal | 25/2/2010 | 16/6/2026 | Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing." | |
| Modificada | Baja (3.3) | 0.33% | — | Becauseinter Bournal | 25/2/2010 | 16/6/2026 | Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal TournamentFrontlines Fuel OF WAR | 19/8/2009 | 16/6/2026 | Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure. | |
| Modificada | Media (4) | 2.2% | 💥 Exploit | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Steve Dawson Pokermax Poker League Tournament Script | 18/10/2008 | 16/6/2026 | configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Burnaware Technologies BurnawareImpressum CdburnerxpNumedia Soft Numedia DVD Burning SDK | 30/9/2008 | 16/6/2026 | NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog… | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Epic Games Unreal Tournament 3 | 25/9/2008 | 16/6/2026 | Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c. | |
| Modificada | Media (5) | 2.6% | — | Epic Games Unreal Tournament 3 | 31/7/2008 | 16/6/2026 | Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Epic Games Unreal Tournament 2004 | 31/7/2008 | 16/6/2026 | Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Ozjournals | 23/1/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the id parameter in a printpreview action. | |
| Modificada | Media (6.8) | 28% | 💥 Exploit | Adodb LiteCmsmadesimple CMS Made SimpleJournalnessOpen-realty+2 | 24/9/2007 | 16/6/2026 | Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Postnuke Software Foundation Postnuke V4bjournal Module | 4/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the v4bJournal module for PostNuke allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a journal_comment action. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Phpbb Journals System Module | 17/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php. | |
| Modificada | Media (4.3) | 0.94% | — | Ozjournals | 11/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.4% | — | Ozjournals | 10/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Elaine Aquino Online Zone Journals (OZJournals) 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) m and (2) c parameters in index.php, (3) a search action, and (4) a "submit comment" action. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Ozjournals | 16/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OZJournals 1.2 allows remote attackers to inject arbitrary web script or HTML via the vname parameter in the comments functionality. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpjournaler | 3/1/2006 | 16/6/2026 | SQL injection vulnerability in index.php in PHPjournaler 1.0 allows remote attackers to execute arbitrary SQL commands via the readold parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Webwiz Database LoginWebwiz JournalWebwiz Site NewsWebwiz Weekly Poll | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Livejournal | 21/12/2005 | 16/6/2026 | Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the… |