Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.6% | — | Bib2html Project Bib2html | 27/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the styleShortName parameter in an adminStyleAdd action to OSBiB/create/index.php. | |
| Modificada | Media (6.8) | 3.5% | — | Debian Ppthtml | 25/4/2014 | 16/6/2026 | Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .ppt file. | |
| Modificada | Media (4.3) | 1.5% | — | Flowplayer Html5 | 24/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote attackers to inject arbitrary web script or HTML by using URL encoding within the callback parameter name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7342. | |
| Modificada | Media (4.3) | 1.5% | — | Flowplayer Html5 | 24/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.1 allows remote attackers to inject arbitrary web script or HTML via the callback parameter, a related issue to CVE-2013-7341. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action. | |
| Modificada | Media (4.3) | 2.0% | — | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | Vasthtml Forumpress | 16/1/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action. | |
| Modificada | Media (4.3) | 5.2% | 💥 Exploit | Dhtmlxspreadsheet | 25/10/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "page" parameter. | |
| Modificada | Media (4.9) | 0.69% | — | Htmlcleaner Project HtmlcleanerOpen-xchange Appsuite | 5/9/2013 | 16/6/2026 | Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending… | |
| Modificada | Media (4.3) | 7.6% | 💥 Exploit | Html2ps Project Html2ps | 10/10/2012 | 16/6/2026 | Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker… | |
| Modificada | Baja (3.5) | 1.7% | — | Authoring Html 6.x-1.0 | 27/6/2012 | 16/6/2026 | classes/Filter/WhitelistedExternalFilter.php in the Authoring HTML module 6.x-1.x before 6.x-1.1 for Drupal does not properly validate sources with the host white list, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks. | |
| Modificada | Media (4.3) | 1.6% | — | Igor Vlasenko Html-template-pro | 6/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters. | |
| Modificada | Baja (2.6) | 1.4% | — | Owasp-java-html-sanitizer Project Owasp-java-html-sanitizer | 17/11/2011 | 16/6/2026 | OWASP HTML Sanitizer (aka owasp-java-html-sanitizer) before 88, when JavaScript is disabled, allows user-assisted remote attackers to obtain potentially sensitive information via a crafted FORM element within a NOSCRIPT element. | |
| Modificada | Media (4.3) | 1.1% | — | Robert Luberda Man2html | 17/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in man2html.cgi.c in man2html 1.6, and possibly other version, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to error messages. | |
| Modificada | Media (5) | 1.4% | — | Htmlpurifier Html Purifier | 23/9/2011 | 16/6/2026 | HTML Purifier 4.2.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/PHPT/Reporter/SimpleTest.php and certain other files. | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Vasthtml Forum Server | 21/2/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in VastHTML Forum Server (aka ForumPress) plugin 1.6.1 and 1.6.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) search_max parameter in a search action to index.php, which is not properly handled by wpf.class.php, (2) id parameter in an… | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Html-edit CMS | 29/12/2010 | 16/6/2026 | Html-edit CMS 3.1.8 allows remote attackers to obtain sensitive information via a direct request to (1) pages.php and (2) menu.php in includes/core_files and (3) extensions/login/frontend/pages/antihacker.php, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Html-edit CMS | 29/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Html-edit CMS | 29/12/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Html-edit CMS 3.1.8 allows remote attackers to execute arbitrary SQL commands via the nuser parameter in a registrate action. | |
| Modificada | Media (4.3) | 0.90% | — | Htmlpurifier | 5/11/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading Style Sheets (CSS) property, a different vulnerability than… | |
| Modificada | Media (4.3) | 2.0% | — | HtmlpurifierMahara | 6/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Htmlcoderhelper COM Graphics | 3/5/2010 | 16/6/2026 | Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | Php.html Kandalf Upper | 29/12/2009 | 16/6/2026 | Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in fileup/. | |
| Modificada | Media (4.3) | 1.7% | — | Derrick Oswald Html-parser | 29/10/2009 | 16/6/2026 | The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character. | |
| Modificada | Alta (9.3) | 5.9% | 💥 Exploit | Konae Alleycode Html Editor | 16/10/2009 | 16/6/2026 | Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to execute arbitrary code via a long value in a TITLE tag. |