Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.5% | 💥 Exploit | Konae Alleycode Html Editor | 16/10/2009 | 16/6/2026 | Stack-based buffer overflow in the Meta Content Optimizer in Konae Technologies Alleycode HTML Editor 2.21 allows user-assisted remote attackers to execute arbitrary code via a long value in a (1) description or (2) keyword META tag. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (10) | 4.4% | — | Htmldoc | 2/9/2009 | 16/6/2026 | Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name,… | |
| Modificada | Media (4.3) | 1.3% | — | Bioinformatics Htmlawed | 3/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Bioinformatics htmLawed 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via invalid Cascading Style Sheets (CSS) expressions in the style attribute, which is processed by Internet Explorer 7. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Microsoft Html Help Workshop | 15/1/2009 | 16/6/2026 | Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | |
| Modificada | Media (4.3) | 1.0% | — | Htmlpurifier | 29/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in smoketests/configForm.php in HTML Purifier before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "unescaped print_r output." | |
| Modificada | Alta (7.5) | 1.4% | — | Phphtmllib | 11/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in examples/widget8.php in phpHtmlLib 2.4.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phphtmllib parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Labs4 Htmleditbox | 27/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in _editor.php in HTMLeditbox 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the settings[app_dir] parameter. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Microsoft Html Help Workshop | 23/1/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Microsoft Html Help Workshop | 19/1/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | KDE Libkhtml | 20/12/2006 | 16/6/2026 | The nodeType function in KDE libkhtml 4.2.0 and earlier, as used by Konquerer, KMail, and other programs, allows remote attackers to cause a denial of service (crash) via malformed HTML tags, possibly involving a COL SPAN tag embedded in a RANGE tag. | |
| Modificada | Baja (2.1) | 0.85% | 💥 Exploit | Php-nuke Autohtml Module | 17/8/2006 | 16/6/2026 | Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation. | |
| Modificada | Media (6.8) | 5.6% | 💥 Exploit | Htmlarea3 | 21/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Lycos Htmlgear Guestgear | 5/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Lycos Tripod htmlGEAR guestGEAR (aka Guest Gear) allows remote attackers to inject arbitrary web script or HTML via a guestbook post containing a javascript URI in the SRC attribute of the BR element after an extra "iframe" tagname within that element, followed by a double… | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Htmljunction Ezhomepagepro | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d)… | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Fuzzymonkey MY BlogM Blom Html-bbcode | 16/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft Html HelpMicrosoft Html Help Workshop | 6/2/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Htmltonuke | 19/1/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter. | |
| Modificada | Media (5) | 1.4% | — | THE PHP Group Pear Html Quickform Controller | 31/12/2005 | 16/6/2026 | The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ihtml Merchant MallAI | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ihtml Merchant | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in merchant.ihtml in iHTML Merchant Version 2 Pro allows remote attackers to execute arbitrary SQL commands via the (1) step, (2) id, and (3) pid parameters. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Oracle Html DB | 14/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers to inject arbitrary web script or HTML, and subsequently execute SQL statements via the (1) p or (2) p_t02 parameters. | |
| Modificada | Media (4.6) | 0.57% | — | Oracle Html DB | 14/10/2005 | 16/6/2026 | The manual installation of Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 stores the SYS password in install.lst in plaintext, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 0.94% | — | Safehtml | 17/8/2005 | 16/6/2026 | SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHTML. | |
| Modificada | Alta (7.5) | 1.7% | — | Htmljunction Ezguestbook | 18/5/2005 | 16/6/2026 | HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password. | |
| Modificada | Media (4.3) | 1.2% | — | Pixel-apes Group Safehtml | 17/5/2005 | 16/6/2026 | The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in applications that rely on SafeHTML for protection. |