Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/pkp/pkp-lib

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-76572 is a medium severity vulnerability in pkp-lib affecting versions 3.3.0-22, 3.4.0-10, and 3.5.0-4. It involves an XML External Entity (XXE) reference issue in the _transformPHP function of classes/xslt/XSLTransformer.php. The vulnerability can be exploited remotely. Fixed versions 3.3.0-23, 3.4.0-11, and 3.5.0-5 address this issue.

Join the discussion
0

A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This vulnerability affects the function setData of the file classes/user/form/APIProfileForm.php of the component API Key Generation. Executing a manipulation of the argument apiKey can lead to insufficient entropy. The attack may be performed from remote. This attack is characterized by high complexity. It is stated that the exploitability is difficult. This patch is called 529b5df878e571ccc727647f7748eafc1466b041. It is best practice to apply a patch to resolve this issue.

Join the discussion
CVE-2024-46326: n/aCVE-2024-46326
0

Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/pkp/pkp-lib
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses