Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

421 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.49%—Jenkins Html Resource13/12/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins HTMLResource Plugin 1.02 and earlier allows attackers to delete arbitrary files on the Jenkins controller file system.
ModificadaMedia (5.4)0.51%—Html-js Doracms8/12/202317/6/2026
An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar.
ModificadaCrítica (9.8)0.81%—Html-js Doracms8/12/202317/6/2026
DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.
ModificadaAlta (8.8)2.4%—Htmlunit4/12/202317/6/2026
HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0
ModificadaMedia (5.4)0.37%—Jonashjalmarsson Html Filter AND Csv-file Search22/11/202317/6/2026
The HTML filter and csv-file search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'csvsearch' shortcode in versions up to, and including, 2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaMedia (6.1)0.57%💥 PoCTypo3 Html SanitizerTypo314/11/202317/6/2026
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4.…
ModificadaAlta (8.8)0.26%—Myrecorp Export WP Page TO Static Html/css10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ReCorp Export WP Page to Static HTML/CSS plugin <= 2.1.9 versions.
ModificadaMedia (6.1)0.41%—Freelancer-coder Wordpress Simple Html Sitemap8/11/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
ModificadaMedia (5.4)0.47%—Simonpedge Slide Anything-responsive Content/html Slider AND Carousel7/11/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in simonpedge Slide Anything – Responsive Content / HTML Slider and Carousel plugin <= 2.4.9 versions.
ModificadaAlta (8.8)0.85%—Jonashjalmarsson Html Filter AND Csv-file Search31/10/202317/6/2026
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7 via the 'src' attribute of the 'csvsearch' shortcode. This allows authenticated attackers, with contributor-level permissions and above, to include and execute arbitrary files on the…
ModificadaMedia (5.4)0.31%—Freelancer-coder Wordpress Simple Html Sitemap18/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ashish Ajani WordPress Simple HTML Sitemap plugin <= 2.1 versions.
ModificadaAlta (8.8)0.21%—Fla-shop Html5 Maps16/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin <= 1.7.1.4 versions.
AnalizadaMedia (5.4)0.39%—Store-opart Multi Html Block14/10/202317/6/2026
Multiple Stored Cross Site Scripting (XSS) vulnerabilities in Opart opartmultihtmlblock before version 2.0.12 and Opart multihtmlblock* version 1.0.0, allows remote authenticated users to inject arbitrary web script or HTML via the body_text or body_text_rude field in /sourcefiles/BlockhtmlClass.php and…
ModificadaMedia (6.1)0.42%—Htmlsanitizer Project Htmlsanitizer5/10/202317/6/2026
HtmlSanitizer is a .NET library for cleaning HTML fragments and documents from constructs that can lead to XSS attacks. The vulnerability occurs in configurations where foreign content is allowed, i.e. either `svg` or `math` are in the list of allowed elements. In the case an application sanitizes user input with a…
ModificadaAlta (8.8)0.25%—Codemiq WP Html Mail3/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions.
ModificadaMedia (6.1)1.5%💥 PoCHtml2pdf Project Html2pdf28/8/202317/6/2026
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
ModificadaAlta (7.5)0.69%—Cloudflare Lol-html16/8/202317/6/2026
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
ModificadaMedia (6.1)0.51%—Typo3 Html Sanitizer25/7/202317/6/2026
TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a…
ModificadaAlta (7.8)0.34%—Htmldoc Project Htmldoc18/7/202317/6/2026
An Out of Bounds flaw was discovered in htmodoc 1.9.12 in function parse_tree() in toc.cxx, this possibly leads to memory layout information leaking in the data. This might be used in a chain of vulnerability in order to reach code execution.
ModificadaAlta (7.8)0.34%—Htmldoc Project Htmldoc18/7/202317/6/2026
A flaw was discovered in htmodoc 1.9.12 in function parse_paragraph in ps-pdf.cxx ,this flaw possibly allows possible code execution and a denial of service via a crafted file.
ModificadaAlta (7.5)1.0%—Htmlcleaner Project Htmlcleaner14/6/202317/6/2026
An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
ModificadaMedia (6.1)0.74%—Codemiq WP Html Mail7/6/202317/6/2026
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an…
ModificadaMedia (6.1)0.58%—Codemiq WP Html Mail7/6/202317/6/2026
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an…
ModificadaAlta (7.5)0.91%—Htmlunit25/5/202317/6/2026
Those using HtmlUnit to browse untrusted webpages may be vulnerable to Denial of service attacks (DoS). If HtmlUnit is running on user supplied web pages, an attacker may supply content that causes HtmlUnit to crash by a stack overflow. This effect may support a denial of service attack.This issue affects htmlunit…
ModificadaAlta (8.8)0.26%—Dogblocker Minify Html23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.
Orbitaley — Vulnerabilidades