Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.14% | — | Livejournal ShortcodeAI | 2/9/2026 | 3/9/2026 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.5) | 0.58% | — | Mediabeta WP JournalAI | 3/3/2025 | 17/6/2026 | Missing Authorization vulnerability in mediabeta WP Journal wpjournal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Journal: from n/a through <= 1.1. | |
| Aplazada | Media (6.9) | 0.45% | — | Blog Botz FOR Journal ThemeAIOpencartAI | 14/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Blog Botz for Journal Theme 1.0 on OpenCart. This affects an unknown part of the file /index.php?route=extension/module/blog_add. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (6.9) | 0.44% | — | Public Knowledge Project Open Journal Systems | 17/8/2024 | 17/6/2026 | A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.41% | — | Matt VAN Andel Adventure JournalAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2. | |
| Analizada | Media (4.7) | 0.44% | — | Remyandrade Workout Journal APP | 20/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php. | |
| Analizada | Media (6.1) | 0.44% | — | Public Knowledge Project Open Journal Systems | 1/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Modificada | Media (6.1) | 0.44% | — | SFU Open Journal Systems | 1/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Analizada | Media (5.4) | 0.41% | — | Pkp.sfu Open Journal Systems | 1/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter. | |
| Analizada | Media (6.1) | 0.53% | — | Pkp.sfu Open Journal Systems | 1/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component. | |
| Analizada | Media (6.1) | 0.52% | — | Pkp.sfu Open Journal Systems | 1/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component. | |
| Modificada | Media (6.1) | 0.48% | — | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 1/2/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php. | |
| Modificada | Media (6.1) | 0.46% | — | Remyandrade Travel Journal Using PHP AND Mysql With Source Code | 1/2/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php. | |
| Modificada | Alta (7.5) | 0.28% | — | Aiven Journalpump | 21/12/2023 | 17/6/2026 | journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential information contained in the configuration if… | |
| Modificada | Alta (8.8) | 0.23% | — | Openjournalsystems Open Journal Systems | 11/12/2023 | 17/6/2026 | A vulnerability has been discovered on OJS, that consists in a CSRF (Cross-Site Request Forgery) attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. | |
| Modificada | Media (5.4) | 0.40% | — | SFU Open Journal Systems | 1/11/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16. | |
| Modificada | Alta (8.8) | 0.26% | — | SFU Open Journal System | 18/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. | |
| Modificada | Media (6.1) | 1.0% | — | Public Knowledge Project Open Journal Systems | 4/4/2022 | 17/6/2026 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. | |
| Modificada | Media (6.1) | 6.1% | — | Public Knowledge Project Open Journal Systems | 1/4/2022 | 17/6/2026 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | |
| Modificada | Media (5.4) | 0.55% | — | Accounting Journal Management Project Accounting Journal Management | 24/2/2022 | 17/6/2026 | Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network. | |
| Modificada | Alta (7.5) | 4.7% | — | Journal-theme Journal | 1/7/2020 | 17/6/2026 | The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors. | |
| Modificada | Alta (8.8) | 1.4% | — | SFU Open Journal System | 19/12/2019 | 17/6/2026 | An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used. | |
| Modificada | Media (6.1) | 1.8% | — | SFU Open Journal System | 12/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field). | |
| Modificada | Crítica (9.8) | 1.8% | — | BD PerformaBD KLA Journal Service | 30/6/2017 | 17/6/2026 | A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of… | |
| Modificada | Media (5.4) | 0.27% | — | Bloodjournal Blood | 20/10/2014 | 17/6/2026 | The Blood (aka com.sheridan.ash) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |