Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.27% | — | Apostrophecms Sanitize-html | 8/9/2025 | 17/6/2026 | `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom `transformTags` option, which is intended to convert attribute values into text. As a result, malicious input can be transformed into… | |
| Aplazada | Media (5.1) | 0.45% | — | Savg-sanitizerAI | 12/8/2025 | 17/6/2026 | savg-sanitizer is a PHP SVG/XML sanitizer. Prior to version 0.22.0, the sanitization logic in the cleanXlinkHrefs method only searches for lower-case attribute name, which allows to by-pass the isHrefSafeValue check. As a result this allows cross-site scripting or linking to external domains. This issue has been… | |
| Aplazada | Media (6.9) | 0.86% | — | Htmlsanitizer.jlAI | 23/6/2025 | 17/6/2026 | HTMLSanitizer.jl is a Whitelist-based HTML sanitizer. Prior to version 0.2.1, when adding the style tag to the whitelist, content inside the tag is incorrectly unescaped, and closing tags injected as content are interpreted as real HTML, enabling tag injection and JavaScript execution. This could result in possible… | |
| Aplazada | Media (5.3) | 0.40% | — | HtmlsanitizerAI | 14/3/2025 | 17/6/2026 | HtmlSanitizer is a client-side HTML Sanitizer. Versions prior to 2.0.3 have a cross-site scripting vulnerability when the sanitizer is used with a `contentEditable` element to set the elements `innerHTML` to a sanitized string produced by the package. If the code is particularly crafted to abuse the code beautifier,… | |
| Aplazada | Crítica (9.3) | 0.75% | — | Path-sanitizerAI | 31/12/2024 | 17/6/2026 | path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the filters can be bypassed using .=%5c which results in a path traversal. This vulnerability is fixed in 3.1.0. | |
| Analizada | Baja (2.3) | 0.45% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.45% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.47% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Analizada | Baja (2.3) | 0.60% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8. The XSS vulnerability with certain configurations of… | |
| Analizada | Baja (2.3) | 0.47% | — | Rubyonrails Rails Html Sanitizers | 2/12/2024 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with Rails >= 7.1.0. A possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer may allow an… | |
| Aplazada | Media (6.1) | 0.55% | — | Html-sanitizerAI | 6/5/2024 | 17/6/2026 | html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons; this allows specially crafted HTML to escape sanitization. The problem has been fixed in… | |
| Analizada | Media (5.3) | 1.0% | — | Apostrophecms Sanitize-htmlFedoraproject Fedora | 24/2/2024 | 17/6/2026 | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system… | |
| Modificada | Media (6.1) | 0.43% | — | Getgrav Dom-sanitizer | 22/11/2023 | 17/6/2026 | DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions. | |
| Modificada | Media (6.1) | 0.57% | 💥 PoC | Typo3 Html SanitizerTypo3 | 14/11/2023 | 17/6/2026 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4.… | |
| Modificada | Media (6.1) | 0.42% | — | Htmlsanitizer Project Htmlsanitizer | 5/10/2023 | 17/6/2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a… | |
| Modificada | Media (6.1) | 0.51% | — | Typo3 Html Sanitizer | 25/7/2023 | 17/6/2026 | TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a… | |
| Modificada | Media (6.1) | 0.71% | — | Sanitize Project SanitizeDebian Linux | 6/7/2023 | 17/6/2026 | Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use the built-in "relaxed" config or when using a custom config that… | |
| Modificada | Media (6.1) | 0.56% | — | Paypal Braintree/sanitize-url | 24/2/2023 | 17/6/2026 | sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. | |
| Modificada | Media (6.1) | 0.53% | — | Sanitize Project Sanitize | 28/1/2023 | 17/6/2026 | Sanitize is an allowlist-based HTML and CSS sanitizer. Versions 5.0.0 and later, prior to 6.0.1, are vulnerable to Cross-site Scripting. When Sanitize is configured with a custom allowlist that allows `noscript` elements, attackers are able to include arbitrary HTML, resulting in XSS (cross-site scripting) or other… | |
| Modificada | Media (6.1) | 0.57% | — | Sanitize-svg Project Sanitize-svg | 4/1/2023 | 17/6/2026 | The `sanitize-svg` package, a small SVG sanitizer to prevent cross-site scripting attacks, uses a deny-list-pattern to sanitize SVGs to prevent XSS. In doing so, literal `<script>`-tags and on-event handlers were detected in versions prior to 0.4.0. As a result, downstream software that relies on `sanitize-svg` and… | |
| Modificada | Media (6.1) | 1.1% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer due to an incomplete fix of CVE-2022-32209. Rails::Html::Sanitizer may allow an attacker to inject content if the… | |
| Modificada | Media (6.1) | 1.0% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags in either… | |
| Modificada | Media (6.1) | 0.89% | — | Rubyonrails Rails Html SanitizersDebian LinuxLoofah Project Loofah | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with Loofah >= 2.1.0. This issue is patched in version 1.4.4. | |
| Modificada | Alta (7.5) | 1.5% | — | Rubyonrails Rails Html SanitizersDebian Linux | 14/12/2022 | 17/6/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service… | |
| Modificada | Media (6.1) | 0.45% | — | Typo3 Html Sanitizer | 13/12/2022 | 17/6/2026 | HTML sanitizer is written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. In versions prior to 1.5.0 or 2.1.1, malicious markup used in a sequence with special HTML CDATA sections cannot be filtered and sanitized due to a parsing issue in the upstream package… |