Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.66% | — | Ossn Open Source Social NetworkAI | 24/4/2026 | 17/6/2026 | Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can upload a specially crafted image with extreme pixel dimensions (e.g., $10000 \times 10000$ pixels). While the compressed file size on disk may be… | |
| Analizada | Media (6.5) | 0.19% | — | Opensource-socialnetwork Open Source Social Network | 5/11/2025 | 17/6/2026 | OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp parameter. | |
| Analizada | Alta (7.3) | 0.27% | — | Opensource-socialnetwork Open Source Social Network | 3/11/2025 | 17/6/2026 | Open Source Social Network (OSSN) 8.6 is vulnerable to Cross Site Scripting (XSS) via the parameter param` at endpoint u/administrator/friends. | |
| Modificada | Alta (7.5) | 1.4% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an HTML injection vulnerability via the location parameter at http://ip_address/:port/ossn/home. | |
| Modificada | Media (5.4) | 1.1% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Group Timeline module. | |
| Modificada | Alta (7.2) | 2.1% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain an arbitrary file upload vulnerability via the component /ossn/administrator/com_installer. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. Note: The project owner believes this is intended behavior… | |
| Modificada | Media (4.8) | 0.89% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the SitePages module. | |
| Modificada | Media (5.4) | 1.1% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the News Feed module. | |
| Modificada | Media (5.4) | 1.1% | — | Openteknik Open Source Social Network | 25/7/2022 | 17/6/2026 | OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users Timeline module. | |
| Modificada | Media (5.9) | 3.8% | — | Opensource-socialnetwork Open Source Social Network | 30/3/2020 | 17/6/2026 | An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the SiteKey to insert… |