Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.95% | — | Express XSS Sanitizer Project Express XSS Sanitizer | 26/9/2022 | 17/6/2026 | The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization. | |
| Modificada | Media (6.1) | 0.82% | — | Typo3 Html Sanitizer | 13/9/2022 | 17/6/2026 | The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explicitly allowed tags, attributes and values. Due to a parsing issue in the upstream package `masterminds/html5`, malicious markup used in a sequence with special HTML comments cannot be filtered and… | |
| Modificada | Alta (7.5) | 1.5% | — | Apostrophecms Sanitize-html | 30/8/2022 | 17/6/2026 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal. | |
| Modificada | Alta (7.5) | 1.5% | — | Lettersanitizer Project Lettersanitizer | 27/6/2022 | 17/6/2026 | lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer below 1.0.2 are affected by a denial of service issue when processing a CSS at-rule `@keyframes`. This package is depended on by [react-letter](https://github.com/mat-sz/react-letter), therefore everyone… | |
| Modificada | Media (6.1) | 30% | — | Rubyonrails Rails Html SanitizersFedoraproject FedoraDebian Linux | 24/6/2022 | 17/6/2026 | # Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability… | |
| Modificada | Media (6.1) | 1.4% | — | Paypal Braintree/sanitize-urlFedoraproject Fedora | 16/3/2022 | 17/6/2026 | The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. | |
| Modificada | Media (6.1) | 0.68% | — | Svg-sanitizer Project Svg-sanitizer | 14/2/2022 | 17/6/2026 | svg-sanitizer is a SVG/XML sanitizer written in PHP. A cross-site scripting vulnerability impacts all users of the `svg-sanitizer` library prior to version 0.15.0. This issue is fixed in version 0.15.0. There is currently no workaround available. | |
| Modificada | Crítica (9.8) | 3.0% | — | Owasp Java Html SanitizerOracle Middleware Common Libraries AND ToolsOracle Primavera Unifier | 18/10/2021 | 17/6/2026 | The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements. | |
| Modificada | Media (5.3) | 1.8% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com". | |
| Modificada | Media (5.3) | 2.0% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. | |
| Modificada | Alta (7.5) | 2.1% | — | Owasp Json-sanitizer | 13/1/2021 | 17/6/2026 | OWASP json-sanitizer before 1.2.2 can output invalid JSON or throw an undeclared exception for crafted input. This may lead to denial of service if the application is not prepared to handle these situations. | |
| Modificada | Crítica (9.8) | 2.1% | — | Owasp Json-sanitizer | 13/1/2021 | 17/6/2026 | OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbitrary HTML or XML into embedding documents. | |
| Modificada | Media (6.1) | 1.0% | — | Htmlsanitizer Project Htmlsanitizer | 4/1/2021 | 17/6/2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. In HtmlSanitizer before version 5.0.372, there is a possible XSS bypass if style tag is allowed. If you have explicitly allowed the `<style>` tag, an attacker could craft HTML that includes script… | |
| Modificada | Alta (7.3) | 1.9% | — | Sanitize Project Sanitize | 16/6/2020 | 17/6/2026 | In Sanitize (RubyGem sanitize) greater than or equal to 3.0.0 and less than 5.2.1, there is a cross-site scripting vulnerability. When HTML is sanitized using Sanitize's "relaxed" config, or a custom config that allows certain elements, some content in a math or svg element may not be sanitized correctly even if math… | |
| Modificada | Media (6.1) | 1.1% | 💥 PoC | Owasp Json-sanitizer | 9/6/2020 | 17/6/2026 | OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be… | |
| Modificada | Media (5.4) | 0.54% | — | Typo3 SVG Sanitizer | 13/5/2020 | 17/6/2026 | The SVG Sanitizer extension for TYPO3 has a cross-site scripting vulnerability in versions before 1.0.3. Slightly invalid or incomplete SVG markup is not correctly processed and thus not sanitized at all. Albeit the markup is not valid it still is evaluated in browsers and leads to cross-site scripting. This is fixed… | |
| Modificada | Media (6.1) | 0.84% | — | Apostrophecms Sanitize-html | 23/1/2020 | 17/6/2026 | sanitize-html before 1.4.3 has XSS. | |
| Modificada | Media (6.1) | 0.74% | — | Svg-sanitizer Project Svg-sanitizer | 11/12/2019 | 17/6/2026 | It is possible to bypass enshrined/svg-sanitize before 0.13.1 using the "xlink:href" attribute due to mishandling of the xlink namespace by the sanitizer. | |
| Modificada | Alta (7.5) | 1.0% | — | Svg-sanitizer Project Svg-sanitizer | 11/11/2019 | 17/6/2026 | darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected whitespace such as in the javascript	:alert substring. | |
| Modificada | Alta (7.5) | 1.4% | — | Drupal SVG Sanitizer | 11/11/2019 | 17/6/2026 | A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled. | |
| Modificada | Media (6.1) | 1.2% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | sanitize-html is a library for scrubbing html input for malicious values Versions 1.2.2 and below have a cross site scripting vulnerability. | |
| Modificada | Media (6.1) | 1.4% | — | Punkave Sanitize-html | 4/6/2018 | 17/6/2026 | Sanitize-html is a library for scrubbing html input of malicious values. Versions 1.11.1 and below are vulnerable to cross site scripting (XSS) in certain scenarios: If allowed at least one nonTextTags, the result is a potential XSS vulnerability. | |
| Modificada | Media (6.1) | 1.3% | — | Rubyonrails Html Sanitizer | 30/3/2018 | 17/6/2026 | There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar… | |
| Modificada | Alta (7.5) | 1.5% | — | Sanitize Project Sanitize | 30/3/2018 | 17/6/2026 | A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element. | |
| Modificada | Media (6.1) | 2.2% | — | Rubyonrails Html Sanitizer | 16/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in lib/rails/html/scrubbers.rb in the rails-html-sanitizer gem before 1.0.3 for Ruby on Rails 4.2.x and 5.x allows remote attackers to inject arbitrary web script or HTML via a crafted CDATA node. |