Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Openmrs Html Form EntryOpenmrs Reference Application | 5/9/2018 | 17/6/2026 | An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0. | |
| Modificada | Crítica (9.8) | 2.2% | — | Html Quickform Project Html QuickformCivicrm | 23/7/2018 | 17/6/2026 | PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in… | |
| Modificada | Alta (7.5) | 2.0% | — | Static-html-server Project Static-html-server | 7/6/2018 | 17/6/2026 | static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Media (6.1) | 1.2% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | |
| Modificada | Media (6.1) | 1.4% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. | |
| Modificada | Media (6.1) | 1.1% | — | Html-janitor Project Html-janitor | 4/6/2018 | 17/6/2026 | html-janitor node module suffers from a Cross-Site Scripting (XSS) vulnerability via clean() accepting user-controlled values. | |
| Modificada | Media (6.1) | 1.0% | — | Theguardian Html-janitor | 4/6/2018 | 17/6/2026 | html-janitor node module suffers from an External Control of Critical State Data vulnerability via user-control of the '_sanitized' variable causing sanitization to be bypassed. | |
| Modificada | Alta (7.5) | 1.1% | — | Ansi2html Project Ansi2html | 31/5/2018 | 17/6/2026 | ansi2html is vulnerable to regular expression denial of service (ReDoS) when certain types of user input is passed in. | |
| Modificada | Crítica (9.8) | 2.2% | — | Html-pages Project Html-pages | 29/5/2018 | 17/6/2026 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL. | |
| Modificada | Media (6.5) | 2.7% | — | Jenkins Html Publisher | 8/5/2018 | 17/6/2026 | A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the Jenkins master. | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Html Sanitizer | 30/3/2018 | 17/6/2026 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar… | |
| Modificada | Media (6.5) | 0.76% | — | Wp-html-sitemap Project Wp-html-sitemap | 19/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete the sitemap via a request to the wp-html-sitemap page in wp-admin/options-general.php. | |
| Modificada | Media (6.1) | 2.2% | — | Html5lib | 22/2/2017 | 17/6/2026 | The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of special characters in attribute values, a different vulnerability than CVE-2016-9909. | |
| Modificada | Media (6.1) | 2.2% | — | Html5lib | 22/2/2017 | 17/6/2026 | The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values. | |
| Modificada | Crítica (9.8) | 4.8% | — | Pear Html Ajax | 6/2/2017 | 17/6/2026 | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression. | |
| Modificada | Media (6.1) | 2.2% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. | |
| Modificada | Media (6.1) | 2.6% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem 1.0.2 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via an HTML entity that is mishandled by the Rails::Html::FullSanitizer class. | |
| Modificada | Media (6.1) | 2.5% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via crafted tag attributes. | |
| Modificada | Baja (2.6) | 2.1% | — | Html-scrubber Project Html-scrubber | 31/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment. | |
| Modificada | Media (5) | 19% | 💥 Exploit | SE Html5 Album Audio Player Project SE Html5 Album Audio Player | 17/6/2015 | 17/6/2026 | Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 1.8% | — | SAP Netweaver Business Client FOR Html | 7/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver Business Client (NWBC) for HTML 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) roundtrips parameter, aka SAP Security Note 2051285. | |
| Modificada | Media (5) | 2.6% | — | Svnlabs Html5 MP3 Player With Playlist Free | 2/12/2014 | 17/6/2026 | The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php. | |
| Modificada | Media (4.3) | 1.6% | — | Html5 Video Player With Playlist Plugin Project Html5 Video Player With Playlist Plugin | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Longtailvideo JW Player FOR Flash & Html5 Video Plugin | 25/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php. | |
| Modificada | Alta (7.5) | 2.7% | — | Jochen Wiedmann Html\ | 4/6/2014 | 16/6/2026 | Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized. |