HtmlUnit records
6 published records for vendor htmlunit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-400 Uncontrolled Resource Consumption1
- CWE-665 Improper Initialization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-26119No exploit | Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, whhtmlunit · htmlunit · CWE-94 | Critical9.8 | — | 2.5% | Apr 3, 2023 |
36Monitor | CVE-2023-49093No exploit | HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTLhtmlunit · htmlunit · CWE-94 | High8.8 | — | 2.4% | Dec 4, 2023 |
33Monitor | CVE-2020-5529No exploit | HtmlUnit prior to 2.37.0 contains code execution vulnerabilities.htmlunit · htmlunit · CWE-665 | High8.1 | — | 4.7% | Feb 11, 2020 |
31Monitor | CVE-2022-28366No exploit | Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory cyberneko html project · cyberneko html | High7.5 | — | 2.1% | Apr 21, 2022 |
30Monitor | CVE-2022-29546No exploit | HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability.htmlunit · htmlunit | High7.5 | — | 1.2% | Apr 24, 2022 |
30Monitor | CVE-2023-2798No exploit | Denial of service in HtmlUnithtmlunit · htmlunit · CWE-400 | High7.5 | — | 0.9% | May 25, 2023 |
- CVE-2023-2611940Plan
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, wh
CriticalCVSS 9.8No exploitEPSS 3%htmlunit · htmlunitApr 3, 2023
- CVE-2023-4909336Monitor
HtmlUnit vulnerable to Remote Code Execution (RCE) via XSTL
HighCVSS 8.8No exploitEPSS 2%htmlunit · htmlunitDec 4, 2023
- CVE-2020-552933Monitor
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities.
HighCVSS 8.1No exploitEPSS 5%htmlunit · htmlunitFeb 11, 2020
- CVE-2022-2836631Monitor
Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory
HighCVSS 7.5No exploitEPSS 2%cyberneko html project · cyberneko htmlApr 21, 2022
- CVE-2022-2954630Monitor
HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability.
HighCVSS 7.5No exploitEPSS 1%htmlunit · htmlunitApr 24, 2022
- CVE-2023-279830Monitor
Denial of service in HtmlUnit
HighCVSS 7.5No exploitEPSS 1%htmlunit · htmlunitMay 25, 2023