Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.9% | 💥 Exploit | Htmly | 13/4/2021 | 17/6/2026 | htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php. | |
| Modificada | Crítica (9.8) | 2.5% | — | Htmldoc Project HtmldocDebian Linux | 5/4/2021 | 17/6/2026 | Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181. | |
| Modificada | Media (5.3) | 2.1% | — | Html-parse-stringify Project Html-parse-stringify | 4/3/2021 | 17/6/2026 | This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process. | |
| Modificada | Media (5.3) | 1.8% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com". | |
| Modificada | Media (5.3) | 2.0% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. | |
| Modificada | Alta (7) | 0.41% | — | Apache Html/java API | 11/1/2021 | 17/6/2026 | There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local… | |
| Modificada | Media (6.1) | 1.0% | — | Htmlsanitizer Project Htmlsanitizer | 4/1/2021 | 17/6/2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script… | |
| Modificada | Alta (8.8) | 0.98% | — | Freehtmldesigns Site Offline | 29/12/2020 | 17/6/2026 | The site-offline plugin before 1.4.4 for WordPress lacks certain wp_create_nonce and wp_verify_nonce calls, aka CSRF. | |
| Modificada | Alta (7.5) | 1.6% | — | Jsreport Phantom-html-to-pdf | 5/11/2020 | 17/6/2026 | This affects the package phantom-html-to-pdf before 0.6.1. | |
| Modificada | Alta (8.8) | 3.1% | — | Openmrs Htmlformentry | 25/9/2020 | 17/6/2026 | A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging path traversal, a malicious Velocity Template Language file could be written to a directory. This file could then be accessed and executed. | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Alta (8.1) | 4.7% | — | HtmlunitDebian LinuxCanonical Ubuntu LinuxApache Camel | 11/2/2020 | 17/6/2026 | HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper… | |
| Modificada | Media (6.1) | 0.84% | — | Apostrophecms Sanitize-html | 23/1/2020 | 17/6/2026 | sanitize-html before 1.4.3 has XSS. | |
| Modificada | Alta (7.8) | 1.1% | — | Htmldoc Project HtmldocDebian LinuxFedoraproject Fedora | 8/12/2019 | 17/6/2026 | HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document. | |
| Modificada | Alta (7.5) | 1.3% | — | Htmlcoin | 5/11/2019 | 17/6/2026 | HTMLCOIN through 2.12 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM. | |
| Modificada | Alta (7.5) | 3.7% | — | S3bubble-amazon-s3-html-5-video-with-adverts | 10/10/2019 | 17/6/2026 | The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter. | |
| Modificada | Media (5.4) | 1.2% | — | Jenkins Html Publisher | 1/10/2019 | 17/6/2026 | Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those. | |
| Modificada | Alta (7.5) | 1.9% | — | Html-pdf Project Html-pdf | 20/9/2019 | 17/6/2026 | The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpRequest to access a file:/// URL. | |
| Modificada | Media (6.5) | 1.1% | — | Myhtml Project Myhtml | 9/9/2019 | 17/6/2026 | MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c. | |
| Modificada | Media (6.8) | 1.3% | 💥 PoC | Atlassian Html Include AND Replace Macro | 14/8/2019 | 17/6/2026 | The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=false XSS protection mechanism via vectors involving an IFRAME element. | |
| Modificada | Alta (8.8) | 1.0% | — | Fla-shop Html5 Maps | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.3% | — | Openmrs-module-htmlformentry | 10/5/2019 | 17/6/2026 | OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation). | |
| Modificada | Media (6.1) | 2.2% | — | Htmly | 8/5/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature. | |
| Modificada | Media (6.1) | 0.69% | — | Html-pages Project Html-pages | 1/2/2019 | 17/6/2026 | A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering. | |
| Modificada | Media (5.4) | 0.79% | — | Html-js Doracms | 6/9/2018 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent. |