Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.33% | — | Man2html Project Man2html | 9/9/2022 | 17/6/2026 | In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the heap. This at least causes the program to segmentation abort if the heap size parameter isn't aligned correctly. In version before GLIBC version 2.29 and aligned correctly, it allows arbitrary write… | |
| Modificada | Alta (7.5) | 1.5% | — | Apostrophecms Sanitize-html | 30/8/2022 | 17/6/2026 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal. | |
| Modificada | Alta (8.1) | 0.97% | — | Htmly | 26/8/2022 | 17/6/2026 | htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php. | |
| Analizada | Crítica (9.8) | 15% | 💥 Exploit | Wkhtmltopdf | 22/8/2022 | 17/6/2026 | wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets. | |
| Modificada | Crítica (9.8) | 1.5% | — | Html-js Doracms | 17/8/2022 | 17/6/2026 | DoraCMS v2.18 and earlier allows attackers to bypass login authentication via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 2.1% | 💥 PoC | WkhtmltopdfDebian Linux | 15/8/2022 | 17/6/2026 | Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations. | |
| Modificada | Media (4.7) | 0.86% | — | Ckeditor5-html-embedCkeditor5-html-supportCkeditor5-markdown-gfm | 3/8/2022 | 17/6/2026 | CKEditor 5 is a JavaScript rich text editor. A cross-site scripting vulnerability has been discovered affecting three optional CKEditor 5's packages in versions prior to 35.0.1. The vulnerability allowed to trigger a JavaScript code after fulfilling special conditions. The affected packages are… | |
| Modificada | Alta (7.5) | 1.7% | — | Htmldoc Project Htmldoc | 18/7/2022 | 17/6/2026 | HTMLDoc v1.9.12 and below was discovered to contain a heap overflow via e_node htmldoc/htmldoc/html.cxx:588. | |
| Modificada | Alta (7.5) | 1.7% | — | Htmldoc Project Htmldoc | 18/7/2022 | 17/6/2026 | HTMLDoc v1.9.15 was discovered to contain a heap overflow via (write_header) /htmldoc/htmldoc/html.cxx:273. | |
| Modificada | Alta (7.5) | 1.1% | — | Split-html-to-chars Project Split-html-to-chars | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Html2wp Project Html2wp | 27/6/2022 | 17/6/2026 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server | |
| Modificada | Media (4.3) | 0.43% | — | Html2wp Project Html2wp | 27/6/2022 | 17/6/2026 | The HTML2WP WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them | |
| Modificada | Alta (8.1) | 0.54% | — | Html2wp Project Html2wp | 27/6/2022 | 17/6/2026 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file | |
| Modificada | Media (6.1) | 30% | — | Rubyonrails Rails Html SanitizersFedoraproject FedoraDebian Linux | 24/6/2022 | 17/6/2026 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability… | |
| Modificada | Media (5.5) | 0.96% | — | Htmldoc Project HtmldocDebian Linux | 9/5/2022 | 17/6/2026 | There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and 'img->height' they are large enough to cause an integer overflow. So, the malloc function may return a heap blosmaller than the expected size, and it will cause a buffer overflow/Address boundary… | |
| Analizada | Alta (7.8) | 1.2% | — | Htmldoc Project Htmldoc | 27/4/2022 | 17/6/2026 | A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS). | |
| Modificada | Alta (7.5) | 1.2% | — | Htmlunit | 25/4/2022 | 17/6/2026 | HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the product. | |
| Modificada | Alta (7.5) | 2.1% | — | Cyberneko Html Project Cyberneko HtmlHtmlunitAntisamy Project Antisamy | 21/4/2022 | 17/6/2026 | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML through 1.9.22 (also affecting OWASP… | |
| Modificada | Alta (7.5) | 2.1% | — | Nekohtml Project NekohtmlOracle Weblogic Server | 11/4/2022 | 17/6/2026 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises a `java.lang.OutOfMemoryError` exception when parsing ill-formed HTML markup. Users are advised to upgrade to `>= 1.9.22.noko2`. Note: The upstream library `org.cyberneko.html` is no longer… | |
| Modificada | Media (5.5) | 0.74% | — | Htmldoc Project HtmldocFedoraproject Fedora | 4/4/2022 | 17/6/2026 | In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. | |
| Modificada | Media (4.8) | 0.56% | — | Htmly | 31/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in htmly.2.8.1 via the Copyright field in the /admin/config page. | |
| Modificada | Media (4.8) | 0.60% | — | Htmly | 31/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in DanPros htmly 2.8.1 via the Description field in (1) admin/config, and (2) index.php pages. | |
| Modificada | Media (5.4) | 0.94% | — | Htmly | 29/3/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profile Module. The manipulation of the field Title with script tags leads to persistent cross site scripting. The attack may be initiated remotely and requires an authentication. A simple POC has been… | |
| Modificada | Media (4.8) | 0.44% | — | Html-js Doracms | 20/3/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/contenttemp of DoraCMS v2.1.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Analizada | Crítica (9.8) | 3.5% | — | Htmldoc Project Htmldoc | 16/3/2022 | 17/6/2026 | A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service. |