Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

421 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Pixel-apes Group Safehtml2/5/200516/6/2026
Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."
ModificadaMedia (4.3)1.3%—Pixel-apes Group Safehtml2/5/200516/6/2026
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaMedia (4.6)0.34%—Toshiaki Kanosue Htmlheadline14/4/200516/6/2026
htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (10)6.2%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
ModificadaAlta (10)9.5%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
ModificadaAlta (10)6.0%—Html2hdml10/1/200516/6/2026
Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file.
ModificadaMedia (5)1.6%—Eekim Cgihtml31/12/200316/6/2026
Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.
ModificadaBaja (2.1)0.33%—Eekim Cgihtml31/12/200316/6/2026
cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.
ModificadaMedia (5)2.6%—Gnome Gtkhtml17/9/200316/6/2026
gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.
ModificadaMedia (5)1.7%—Gnome Gtkhtml5/5/200316/6/2026
GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.
ModificadaMedia (4.3)3.5%💥 ExploitAestiva Html OS2/4/200316/6/2026
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message.
ModificadaMedia (4.3)1.7%💥 ExploitLycos Htmlgear Guestgear2/4/200316/6/2026
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.
ModificadaAlta (7.5)3.9%💥 ExploitAGH Htmlsearch31/12/200216/6/2026
search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter.
ModificadaAlta (7.5)1.0%—F2html.pl31/12/200216/6/2026
SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names.
ModificadaAlta (7.5)9.2%💥 ExploitHtml2ps Project Html2ps12/11/200216/6/2026
Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input."
ModificadaAlta (7.5)10%💥 ExploitRandy Parker Power UP Html7/9/200116/6/2026
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.
ModificadaMedia (5)3.6%💥 ExploitJCS WEB Works Multihtml19/12/200023/9/2026
MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter.
ModificadaAlta (7.5)1.9%—Ihtml Merchant16/9/199916/6/2026
iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error.
ModificadaMedia (4.6)0.31%—Earl Hood Man2htmlDebian Linux20/8/199916/6/2026
Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (5)6.0%💥 ExploitMiva Htmlscript27/1/199816/6/2026
htmlscript CGI program allows remote read access to files.
Orbitaley — Vulnerabilidades