Show filters
39 Total Results
Displaying 11-20 of 39
Sort by:
Attacker Value
Unknown

CVE-2023-2863

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229819.
Attacker Value
Unknown

CVE-2022-26616

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
Attacker Value
Unknown

CVE-2022-24181

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
Attacker Value
Unknown

CVE-2022-24582

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of the network.
Attacker Value
Unknown

CVE-2020-15478

Disclosure Date: July 01, 2020 (last updated February 21, 2025)
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
Attacker Value
Unknown

CVE-2019-19909

Disclosure Date: December 19, 2019 (last updated November 27, 2024)
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
Attacker Value
Unknown

CVE-2018-12229

Disclosure Date: June 12, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Public Knowledge Project (PKP) Open Journal System (OJS) 3.0.0 to 3.1.1-1 allows remote attackers to inject arbitrary web script or HTML via the templates/frontend/pages/search.tpl parameter (aka the By Author field).
0
Attacker Value
Unknown

CVE-2017-6022

Disclosure Date: June 30, 2017 (last updated November 26, 2024)
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior versions. They use hard-coded passwords to access the BD Kiestra Database, which could be leveraged to compromise the confidentiality of limited PHI/PII information stored in the BD Kiestra Database.
0
Attacker Value
Unknown

CVE-2014-7116

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The NRA Journal (aka com.magazinecloner.nationalrifleassociationjournal) application @7F080181 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7122

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Lansing State Journal Print (aka com.lansingjournal.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0