Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.26% | — | Public Knowledge Project OMPAIPublic Knowledge Project OJSAI | 20/11/2025 | 17/6/2026 | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross… | |
| Aplazada | Crítica (9.8) | 0.41% | — | Public Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI | 24/2/2025 | 17/6/2026 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin. | |
| Aplazada | Media (5.4) | 0.36% | — | Public Knowledge Project PKP PlatformAIPublic Knowledge Project OJSAIPublic Knowledge Project OMPAIPublic Knowledge Project OPSAI | 22/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a crafted script | |
| Aplazada | Media (6.1) | 0.48% | — | Public Knowledge Project Pkp-libAI | 21/10/2024 | 17/6/2026 | Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function. | |
| Analizada | Media (6.9) | 0.44% | — | Public Knowledge Project Open Journal Systems | 17/8/2024 | 17/6/2026 | A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.44% | — | Public Knowledge Project Open Journal Systems | 1/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. | |
| Modificada | Media (6.1) | 1.0% | — | Public Knowledge Project Open Journal Systems | 4/4/2022 | 17/6/2026 | PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers. | |
| Modificada | Media (6.1) | 6.1% | — | Public Knowledge Project Open Journal Systems | 1/4/2022 | 17/6/2026 | Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | |
| Modificada | Media (6.1) | 1.6% | — | Public Knowledge Project Open Monograph Press | 19/6/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in templates/frontend/pages/searchResults.tpl in Public Knowledge Project (PKP) Open Monograph Press (OMP) v1.2.0 through 3.1.1-2 before 3.1.1-3 allows remote attackers to inject arbitrary web script or HTML via the catalog.noTitlesSearch parameter (aka the Search field). | |
| Modificada | Media (6.8) | 2.0% | — | Public Knowledge Project Open Harvester Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Harvester Systems 2.3.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | |
| Modificada | Media (6.8) | 1.3% | — | Public Knowledge Project Open Journal Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files. | |
| Modificada | Media (6.8) | 1.1% | — | Public Knowledge Project Open Conference Systems | 23/9/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Conference Systems 2.3.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload a PHP file. |