Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

421 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.5%—Htmlunit3/4/202317/6/2026
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
ModificadaMedia (6.1)0.55%—Esdoc-publish-html-plugin21/2/202317/6/2026
esdoc-publish-html-plugin is a plugin for the document maintenance software ESDoc. TheHTML sanitizer in esdoc-publish-html-plugin 1.1.2 and prior can be bypassed which may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
ModificadaMedia (5.4)0.57%—Bplugins Html5 Audio Player6/2/202317/6/2026
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (7.5)1.1%—Html-stripscripts Project Html-stripscriptsDebian Linux21/1/202317/6/2026
The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.
ModificadaMedia (6.1)0.41%—Phoenixframework Phoenix Html10/1/202317/6/2026
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
ModificadaMedia (6.1)0.53%—Json2html28/12/202217/6/2026
A vulnerability was found in moappi Json2html up to 1.1.x and classified as problematic. This issue affects some unknown processing of the file json2html.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 1.2.0 is able to address this issue. The name of the…
ModificadaMedia (6.1)0.93%—Openmrs Htmlformentryui27/12/202217/6/2026
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name…
ModificadaMedia (4.8)0.54%—Kwayyinfotech Kwayy Html Sitemap26/12/202217/6/2026
The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaMedia (5.4)0.48%—Wphowto Videojs Html5 Player19/12/202217/6/2026
The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)1.1%—Rubyonrails Rails Html SanitizersDebian Linux14/12/202217/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the…
ModificadaMedia (6.1)1.0%—Rubyonrails Rails Html SanitizersDebian Linux14/12/202217/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either…
ModificadaMedia (6.1)0.89%—Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah14/12/202217/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4.
ModificadaAlta (7.5)1.5%—Rubyonrails Rails Html SanitizersDebian Linux14/12/202217/6/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service…
ModificadaMedia (6.1)0.45%—Typo3 Html Sanitizer13/12/202217/6/2026
HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1, malicious markup used in a sequence with special HTML CDATA sections cannot be filtered and sanitized due to a parsing issue in the upstream package…
AnalizadaAlta (7.2)1.9%💥 PoCLinksoftwarellc Html Forms28/11/202217/6/2026
The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users
ModificadaMedia (5.5)0.59%—Htmldoc Project Htmldoc14/11/202217/6/2026
A heap buffer overflow in image_set_mask function of HTMLDOC before 1.9.15 allows an attacker to write outside the buffer boundaries.
ModificadaAlta (8.1)1.1%💥 PoCHtml2xhtml Project Html2xhtml8/11/202217/6/2026
html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo) at procesador.c. This vulnerability allows attackers to access sensitive files or cause a Denial of Service (DoS) via a crafted html file.
ModificadaMedia (5.5)0.27%—Rtf2html Project Rtf2html31/10/202217/6/2026
rtf2html v0.2.0 was discovered to contain a heap overflow in the component /rtf2html/./rtf_tools.h.
ModificadaAlta (7.5)1.2%—Html-minifier-terserKangax Html-minifier31/10/202217/6/2026
A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.
ModificadaCrítica (9.8)1.3%—Democritus D8s-html11/10/202217/6/2026
The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
ModificadaAlta (8.1)1.5%—Htmly30/9/202217/6/2026
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.
ModificadaCrítica (9.8)1.4%—D8s-html Project D8s-html19/9/202217/6/2026
The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
ModificadaMedia (4.3)1.6%💥 ExploitFreehtmldesigns Site Offline19/9/202217/6/2026
The Site Offline Or Coming Soon Or Maintenance Mode WordPress plugin before 1.5.3 prevents users from accessing a website but does not do so if the URL contained certain keywords. Adding those keywords to the URL's query string would bypass the plugin's main feature.
ModificadaMedia (6.1)0.82%—Typo3 Html Sanitizer13/9/202217/6/2026
The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and…
ModificadaMedia (5.5)0.33%—Man2html Project Man2html9/9/202217/6/2026
In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, fd_nextsize, bk_nextsize of the current chunk. The next chunk is then freed later on, causing a freeing of an arbitrary amount of memory.
Orbitaley — Vulnerabilidades