Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
421 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.49% | — | Jenkins Html Resource | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.51% | — | Html-js Doracms | 8/12/2023 | 17/6/2026 | An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar. | |
| Modificada | Crítica (9.8) | 0.81% | — | Html-js Doracms | 8/12/2023 | 17/6/2026 | DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack. | |
| Modificada | Alta (8.8) | 2.4% | — | Htmlunit | 4/12/2023 | 17/6/2026 | HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0 | |
| Modificada | Media (5.4) | 0.37% | — | Jonashjalmarsson Html Filter AND Csv-file Search | 22/11/2023 | 17/6/2026 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'csvsearch' shortcode in versions up to, and including, 2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (6.1) | 0.57% | 💥 PoC | Typo3 Html SanitizerTypo3 | 14/11/2023 | 17/6/2026 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4.… | |
| Modificada | Alta (8.8) | 0.26% | — | Myrecorp Export WP Page TO Static Html/css | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions. | |
| Modificada | Media (6.1) | 0.41% | — | Freelancer-coder Wordpress Simple Html Sitemap | 8/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Simonpedge Slide Anything-responsive Content/html Slider AND Carousel | 7/11/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions. | |
| Modificada | Alta (8.8) | 0.85% | — | Jonashjalmarsson Html Filter AND Csv-file Search | 31/10/2023 | 17/6/2026 | The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the… | |
| Modificada | Media (5.4) | 0.31% | — | Freelancer-coder Wordpress Simple Html Sitemap | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Fla-shop Html5 Maps | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin <= 1.7.1.4 versions. | |
| Analizada | Media (5.4) | 0.39% | — | Store-opart Multi Html Block | 14/10/2023 | 17/6/2026 | Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and… | |
| Modificada | Media (6.1) | 0.42% | — | Htmlsanitizer Project Htmlsanitizer | 5/10/2023 | 17/6/2026 | HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a… | |
| Modificada | Alta (8.8) | 0.25% | — | Codemiq WP Html Mail | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions. | |
| Modificada | Media (6.1) | 1.5% | 💥 PoC | Html2pdf Project Html2pdf | 28/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php. | |
| Modificada | Alta (7.5) | 0.69% | — | Cloudflare Lol-html | 16/8/2023 | 17/6/2026 | lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected. | |
| Modificada | Media (6.1) | 0.51% | — | Typo3 Html Sanitizer | 25/7/2023 | 17/6/2026 | TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a… | |
| Modificada | Alta (7.8) | 0.34% | — | Htmldoc Project Htmldoc | 18/7/2023 | 17/6/2026 | An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution. | |
| Modificada | Alta (7.8) | 0.34% | — | Htmldoc Project Htmldoc | 18/7/2023 | 17/6/2026 | A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file. | |
| Modificada | Alta (7.5) | 1.0% | — | Htmlcleaner Project Htmlcleaner | 14/6/2023 | 17/6/2026 | An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. | |
| Modificada | Media (6.1) | 0.74% | — | Codemiq WP Html Mail | 7/6/2023 | 17/6/2026 | The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an… | |
| Modificada | Media (6.1) | 0.58% | — | Codemiq WP Html Mail | 7/6/2023 | 17/6/2026 | The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an… | |
| Modificada | Alta (7.5) | 0.91% | — | Htmlunit | 25/5/2023 | 17/6/2026 | Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit… | |
| Modificada | Alta (8.8) | 0.26% | — | Dogblocker Minify Html | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability. |