Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

421 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.9%💥 ExploitHtmly13/4/202117/6/2026
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
ModificadaCrítica (9.8)2.5%—Htmldoc Project HtmldocDebian Linux5/4/202117/6/2026
Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181.
ModificadaMedia (5.3)2.1%—Html-parse-stringify Project Html-parse-stringify4/3/202117/6/2026
This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.
ModificadaMedia (5.3)1.8%—Apostrophecms Sanitize-html8/2/202117/6/2026
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
ModificadaMedia (5.3)2.0%—Apostrophecms Sanitize-html8/2/202117/6/2026
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
ModificadaAlta (7)0.41%—Apache Html/java API11/1/202117/6/2026
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local…
ModificadaMedia (6.1)1.0%—Htmlsanitizer Project Htmlsanitizer4/1/202117/6/2026
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script…
ModificadaAlta (8.8)0.98%—Freehtmldesigns Site Offline29/12/202017/6/2026
The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF.
ModificadaAlta (7.5)1.6%—Jsreport Phantom-html-to-pdf5/11/202017/6/2026
This affects the package phantom-html-to-pdf before 0.6.1.
ModificadaAlta (8.8)3.1%—Openmrs Htmlformentry25/9/202017/6/2026
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed.
ModificadaAlta (7.4)7.2%—Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+18/6/202017/6/2026
GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the…
ModificadaAlta (8.1)4.7%—HtmlunitDebian LinuxCanonical Ubuntu LinuxApache Camel11/2/202017/6/2026
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper…
ModificadaMedia (6.1)0.84%—Apostrophecms Sanitize-html23/1/202017/6/2026
sanitize-html before 1.4.3 has XSS.
ModificadaAlta (7.8)1.1%—Htmldoc Project HtmldocDebian LinuxFedoraproject Fedora8/12/201917/6/2026
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.
ModificadaAlta (7.5)1.3%—Htmlcoin5/11/201917/6/2026
HTMLCOIN through 2.12 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
ModificadaAlta (7.5)3.7%—S3bubble-amazon-s3-html-5-video-with-adverts10/10/201917/6/2026
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
ModificadaMedia (5.4)1.2%—Jenkins Html Publisher1/10/201917/6/2026
Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.
ModificadaAlta (7.5)1.9%—Html-pdf Project Html-pdf20/9/201917/6/2026
The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL.
ModificadaMedia (6.5)1.1%—Myhtml Project Myhtml9/9/201917/6/2026
MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.
ModificadaMedia (6.8)1.3%💥 PoCAtlassian Html Include AND Replace Macro14/8/201917/6/2026
The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element.
ModificadaAlta (8.8)1.0%—Fla-shop Html5 Maps5/7/201917/6/2026
Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaCrítica (9.8)2.3%—Openmrs-module-htmlformentry10/5/201917/6/2026
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
ModificadaMedia (6.1)2.2%—Htmly8/5/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.
ModificadaMedia (6.1)0.69%—Html-pages Project Html-pages1/2/201917/6/2026
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
ModificadaMedia (5.4)0.79%—Html-js Doracms6/9/201817/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
Orbitaley — Vulnerabilidades