sfu CVE 脆弱性と CVE 一覧(18)

製品(CPE): — CVE 件数: 18

sfu 脆弱性概要

sfu 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

一般的な弱点パターンには vendor risk cross-site scripting and vendor risk csrf があり、vendor surface production workloads and vendor surface software deployment の利用場面で vendor impact session compromise などのリスクが生じる可能性があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 118 / 18 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2024-25436 A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. [email protected] 6.1 0.44% 2024-03-01 2025-03-28
CVE-2023-5904 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.45% 2023-11-07 2024-11-21
CVE-2023-5903 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.35% 2023-11-07 2024-11-21
CVE-2023-5902 Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 4.3 0.26% 2023-11-07 2024-11-21
CVE-2023-5901 Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 3.5 0.46% 2023-11-07 2024-11-21
CVE-2023-5900 Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 3.5 0.24% 2023-11-07 2024-11-21
CVE-2023-47271 PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image. [email protected] 5.3 0.62% 2023-11-06 2024-11-21
CVE-2023-5897 Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1. [email protected] 8.8 0.22% 2023-11-01 2024-11-21
CVE-2023-5896 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4. [email protected] 5.4 0.34% 2023-11-01 2024-11-21
CVE-2023-5895 Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.41% 2023-11-01 2024-11-21
CVE-2023-5894 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16. [email protected] 5.4 0.40% 2023-11-01 2024-11-21
CVE-2023-5893 Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 8.8 0.26% 2023-11-01 2024-11-21
CVE-2023-5892 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.40% 2023-11-01 2024-11-21
CVE-2023-5891 Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.40% 2023-11-01 2024-11-21
CVE-2023-5890 Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16. [email protected] 5.4 0.40% 2023-11-01 2024-11-21
CVE-2023-5626 Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16. [email protected] 8.8 0.26% 2023-10-18 2024-11-21
CVE-2019-19909 An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used. [email protected] 8.8 1.39% 2019-12-19 2024-11-21
CVE-2018-12229 Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field). [email protected] 6.1 1.80% 2018-06-12 2024-11-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence