Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

421 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.4%—Htmldoc Project Htmldoc16/3/202217/6/2026
A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.
ModificadaMedia (4.8)0.60%—Html5 Responsive FAQ Project Html5 Responsive FAQ14/3/202217/6/2026
The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaAlta (7.8)0.84%—Htmldoc Project Htmldoc3/3/202217/6/2026
Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.
ModificadaAlta (7.8)1.2%—Htmldoc Project Htmldoc3/3/202217/6/2026
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.
ModificadaAlta (7.8)1.5%—Htmldoc Project Htmldoc2/3/202217/6/2026
A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
ModificadaAlta (7.8)1.1%—Htmldoc Project Htmldoc2/3/202217/6/2026
A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.
ModificadaAlta (7.8)1.4%—Htmldoc Project Htmldoc2/3/202217/6/2026
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.
ModificadaMedia (5.4)1.1%💥 PoCHtmly1/3/20229/7/2026
A cross-site scripting (XSS) vulnerability in Htmly v2.8.1 allows attackers to excute arbitrary web scripts HTML via a crafted payload in the content field of a blog post.
ModificadaAlta (7.8)0.96%—Htmldoc Project HtmldocRedhat Enterprise LinuxFedoraproject Fedora24/2/202217/6/2026
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
ModificadaMedia (5.5)0.94%—Htmldoc Project HtmldocDebian Linux9/2/202217/6/2026
A vulnerability was found in htmldoc version 1.9.15 where the stack out-of-bounds read takes place in gif_get_code() and occurs when opening a malicious GIF file, which can result in a crash (segmentation fault).
ModificadaAlta (8.8)1.6%—Html2pdf Project Html2pdf18/1/202217/6/2026
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.
ModificadaAlta (7.8)7.3%💥 ExploitHtmldoc Project HtmldocDebian Linux10/1/202217/6/2026
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.
ModificadaCrítica (9.8)1.2%—Html-to-csv Project Html-to-csv26/11/202117/6/2026
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via CSV files.
ModificadaMedia (5.5)0.94%—Htmldoc Project HtmldocDebian Linux3/11/202117/6/2026
A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
ModificadaCrítica (9.8)3.0%—Owasp Java Html SanitizerOracle Middleware Common Libraries AND ToolsOracle Primavera Unifier18/10/202117/6/2026
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
ModificadaMedia (5.4)0.65%—Bplugins Html5 Audio Player18/10/202117/6/2026
The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode
ModificadaMedia (5.4)1.8%💥 PoCWP Html Author BIO Project WP Html Author BIO11/10/202117/6/2026
The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site…
ModificadaMedia (6.1)1.1%—Remark-html7/9/202117/6/2026
remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of remark-html has mentioned that it was safe by default. In practice the default was never safe and had to be opted into. That is, user input was not sanitized. This means arbitrary HTML can be passed…
ModificadaAlta (7.5)2.0%—Ansi-html Project Ansi-html18/8/202117/6/2026
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
ModificadaMedia (6.1)0.93%—Htmly3/8/202117/6/2026
The "blog title" field in the "Settings" menu "config" page of "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send an authenticated post HTTP request to admin/config and inject arbitrary web script or HTML through a special website name.
ModificadaMedia (6.1)0.93%—Htmly3/8/202117/6/2026
The "content" field in the "regular post" page of the "add content" menu under "dashboard" in htmly 2.8.1 has a storage cross site scripting (XSS) vulnerability. It allows remote attackers to send authenticated post-http requests to add / content and inject arbitrary web scripts or HTML through special content.
ModificadaCrítica (9.1)1.6%—Htmly3/8/202117/6/2026
In htmly version 2.8.1, is vulnerable to an Arbitrary File Deletion on the local host when delete backup files. The vulnerability may allow a remote attacker to delete arbitrary know files on the host.
ModificadaMedia (4.3)43%—Jenkins Selenium Html Report30/6/202117/6/2026
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (6.5)1.4%—Htmly21/5/202117/6/2026
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
ModificadaAlta (7.5)0.41%—Html-js Doracms20/5/202117/6/2026
Weak Encoding for Password in DoraCMS v2.1.1 and earlier allows attackers to obtain sensitive information as it does not use a random salt or IV for its AES-CBC encryption, causes password encrypted for users to be susceptible to dictionary attacks.
Orbitaley — Vulnerabilidades