Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Pixel-apes Group Safehtml | 2/5/2005 | 16/6/2026 | Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities." | |
| Modificada | Media (4.3) | 1.3% | — | Pixel-apes Group Safehtml | 2/5/2005 | 16/6/2026 | Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol." | |
| Modificada | Alta (7.5) | 3.0% | — | Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+18 | 27/4/2005 | 16/6/2026 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. | |
| Modificada | Media (4.6) | 0.34% | — | Toshiaki Kanosue Htmlheadline | 14/4/2005 | 16/6/2026 | htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (10) | 6.2% | — | Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+12 | 27/1/2005 | 16/6/2026 | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888. | |
| Modificada | Alta (10) | 9.5% | — | Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+12 | 27/1/2005 | 16/6/2026 | Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889. | |
| Modificada | Alta (10) | 6.0% | — | Html2hdml | 10/1/2005 | 16/6/2026 | Buffer overflow in the remove_quote function in convert.c for html2hdml 1.0.3 allows remote attackers to execute arbitrary code via a crafted HTML file. | |
| Modificada | Media (5) | 1.6% | — | Eekim Cgihtml | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads. | |
| Modificada | Baja (2.1) | 0.33% | — | Eekim Cgihtml | 31/12/2003 | 16/6/2026 | cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files. | |
| Modificada | Media (5) | 2.6% | — | Gnome Gtkhtml | 17/9/2003 | 16/6/2026 | gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference. | |
| Modificada | Media (5) | 1.7% | — | Gnome Gtkhtml | 5/5/2003 | 16/6/2026 | GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Aestiva Html OS | 2/4/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script by inserting the script after a trailing / character, which inserts the script into the resulting error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Lycos Htmlgear Guestgear | 2/4/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | AGH Htmlsearch | 31/12/2002 | 16/6/2026 | search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | F2html.pl | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in f2html.pl 0.1 through 0.4 allows remote attackers to execute arbitrary SQL commands via file names. | |
| Modificada | Alta (7.5) | 9.2% | 💥 Exploit | Html2ps Project Html2ps | 12/11/2002 | 16/6/2026 | Unknown vulnerability in html2ps HTML/PostScript converter 1.0, when used within LPRng, allows remote attackers to execute arbitrary code via "unsanitized input." | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Randy Parker Power UP Html | 7/9/2001 | 16/6/2026 | Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | JCS WEB Works Multihtml | 19/12/2000 | 23/9/2026 | MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifying the file name to the "multi" parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Ihtml Merchant | 16/9/1999 | 16/6/2026 | iHTML Merchant allows remote attackers to obtain sensitive information or execute commands via a code parsing error. | |
| Modificada | Media (4.6) | 0.31% | — | Earl Hood Man2htmlDebian Linux | 20/8/1999 | 16/6/2026 | Man2html 2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Miva Htmlscript | 27/1/1998 | 16/6/2026 | htmlscript CGI program allows remote read access to files. |