Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | — | CkeditorDrupalOracle Application ExpressOracle Commerce Merchandising+5 | 16/3/2022 | 17/6/2026 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorDrupalOracle Application ExpressOracle Commerce Merchandising+5 | 16/3/2022 | 17/6/2026 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could… | |
| Modificada | Media (5.4) | 1.3% | — | CkeditorDebian LinuxFedoraproject FedoraOracle Application Express+8 | 13/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+6 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary… | |
| Modificada | Media (5.4) | 1.2% | — | CkeditorFedoraproject FedoraOracle Application ExpressOracle Banking Party Management+9 | 12/8/2021 | 17/6/2026 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It… | |
| Modificada | Media (6.5) | 2.2% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+6 | 26/1/2021 | 25/8/2026 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin). | |
| Modificada | Media (6.1) | 2.0% | — | CkeditorOracle Agile Product Lifecycle ManagementOracle Application ExpressOracle Banking Party Management+5 | 12/11/2020 | 25/8/2026 | A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs. | |
| Modificada | Media (6.5) | 1.0% | — | Oracle Commerce Merchandising | 23/4/2019 | 17/6/2026 | Vulnerability in the Oracle Commerce Merchandising component of Oracle Commerce (subcomponent: Asset Manager). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Merchandising. Successful… |