Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.38%—Jpatokal Openflights29/8/202417/6/2026
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php
ModificadaMedia (6.1)0.29%—Jpatokal Openflights29/8/202417/6/2026
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php
ModificadaMedia (5.4)0.28%—Jpatokal Openflights29/8/202417/6/2026
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php
ModificadaMedia (5.4)0.28%—Jpatokal Openflights29/8/202417/6/2026
openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
ModificadaCrítica (9.8)0.85%—Justsystems Atok Medical 2Justsystems Atok Medical 3Justsystems Atok PRO 3Justsystems Atok PRO 4+5616/8/202217/6/2026
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious file may be executed with the privilege of…
ModificadaAlta (7.5)1.0%—Csa-estate Csatoken9/7/201817/6/2026
The mintToken function of a smart contract implementation for CSAToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Ladatoken Project Ladatoken5/7/201817/6/2026
The mintToken function of a smart contract implementation for LadaToken (LDT), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)0.92%—Plazatoken Project Plazatoken3/7/201817/6/2026
The mintToken function of a smart contract implementation for Plaza Token (PLAZA), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.2)0.39%—Justsystems AtokJustsystems Atok Flat-rate ServiceJustsystems Just Smile18/1/201316/6/2026
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications."
ModificadaMedia (4.3)1.2%—Justsystems Atok28/9/201216/6/2026
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.