Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.26%—Public Knowledge Project OMPAIPublic Knowledge Project OJSAI20/11/202517/6/2026
A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross…
AplazadaCrítica (9.8)0.41%—Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI24/2/202517/6/2026
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
AplazadaMedia (5.4)0.36%—Public Knowledge Project PKP PlatformAIPublic Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI22/11/202417/6/2026
Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script
AplazadaMedia (6.1)0.48%—Public Knowledge Project Pkp-libAI21/10/202417/6/2026
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
AnalizadaMedia (6.9)0.44%—Public Knowledge Project Open Journal Systems17/8/202417/6/2026
A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (6.1)0.44%—Public Knowledge Project Open Journal Systems1/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.
ModificadaMedia (6.1)1.0%—Public Knowledge Project Open Journal Systems4/4/202217/6/2026
PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.
ModificadaMedia (6.1)6.1%—Public Knowledge Project Open Journal Systems1/4/202217/6/2026
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
ModificadaMedia (6.1)1.6%—Public Knowledge Project Open Monograph Press19/6/201817/6/2026
Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP) Open Monograph Press (OMP) v1.2.0 through 3.1.1-2 before 3.1.1-3 allows remote attackers to inject arbitrary web script or HTML via the catalog.noTitlesSearch parameter (aka the Search field).
ModificadaMedia (6.8)2.0%—Public Knowledge Project Open Harvester Systems23/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.
ModificadaMedia (6.8)1.3%—Public Knowledge Project Open Journal Systems23/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.
ModificadaMedia (6.8)1.1%—Public Knowledge Project Open Conference Systems23/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file.