Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.54% | — | Apryse Html2pdf | 22/1/2026 | 5/7/2026 | An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server. | |
| Modificada | Alta (7.5) | 0.47% | — | Apryse Html2pdf | 22/1/2026 | 5/7/2026 | A Local File Inclusion (LFI) and a Server-Side Request Forgery (SSRF) vulnerability was found in the InsertFromHtmlString() function of the Apryse HTML2PDF SDK thru 11.6.0. These vulnerabilities could allow an attacker to read local files on the server or make arbitrary HTTP requests to internal or external services.… | |
| Analizada | Alta (8.7) | 0.38% | — | Ekoopmans Html2pdf.js | 14/1/2026 | 17/6/2026 | html2pdf.js converts any webpage or element into a printable PDF entirely client-side. Prior to 0.14.0, html2pdf.js contains a cross-site scripting (XSS) vulnerability when given a text source rather than an element. This text is not sufficiently sanitized before being attached to the DOM, allowing malicious scripts… | |
| Aplazada | Alta (7.5) | 0.64% | — | Xhtml2pdfAI | 8/10/2024 | 5/7/2026 | An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string. | |
| Modificada | Alta (7.5) | 0.69% | — | Kumaf Pyhtml2pdf | 20/2/2024 | 17/6/2026 | Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. | |
| Modificada | Media (6.1) | 1.5% | — | Html2pdf Project Html2pdf | 28/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php. | |
| Modificada | Alta (8.8) | 1.6% | — | Html2pdf Project Html2pdf | 18/1/2022 | 17/6/2026 | An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document. |