Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAIUnknown Vendor Product FirmwareAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | |
| Aplazada | Crítica (9.1) | 0.44% | — | LighttpdAI | 4/8/2026 | 9/9/2026 | The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing. | |
| Aplazada | Alta (7.4) | 0.79% | — | Wavlink Wn572AIWavlink Wn570hAIWavlink Wn573AIWavlink Wn529AI+8 | 3/8/2026 | 12/8/2026 | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument… | |
| Aplazada | Alta (8.9) | 1.1% | — | Totolink Nr1800xAILighttpdAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Media (6.3) | 0.32% | — | Nghttp2 | 28/6/2026 | 30/6/2026 | nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the… | |
| Aplazada | Alta (8.9) | 1.0% | — | Totolink Nr1800xAILighttpdAI | 1/5/2026 | 17/6/2026 | A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly… | |
| Modificada | Alta (7.5) | 0.89% | — | Nghttp2 | 18/3/2026 | 15/7/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called… | |
| Aplazada | Crítica (9.8) | 0.76% | — | LighttpdAI | 9/2/2026 | 17/6/2026 | An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections. | |
| Analizada | Media (6.9) | 0.37% | — | Lighttpd | 3/11/2025 | 17/6/2026 | lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: This issue affects lighttpd1.4.80 | |
| Aplazada | Baja (3.7) | 0.29% | — | Nghttp2AIPowerdns DnsdistAI | 18/9/2025 | 17/6/2026 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources. | |
| Aplazada | Crítica (9.3) | 4.4% | 💥 Exploit | LighttpdAIDlink Dsp-w110a1AI | 16/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating… | |
| Aplazada | Alta (7.5) | 2.3% | — | Nghttp2AIH2OAIPowerdns DnsdistAI | 29/4/2025 | 17/6/2026 | When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to… | |
| Aplazada | Alta (7.7) | 0.29% | — | LighttpdAI | 25/4/2025 | 17/6/2026 | The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted… | |
| Aplazada | Alta (7.1) | 0.39% | — | Trendnet Ti-g102iAILighttpdAI | 30/3/2025 | 17/6/2026 | A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be done within the… | |
| Aplazada | Media (5.3) | 0.67% | — | LighttpdAI | 17/6/2024 | 17/6/2026 | There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests. | |
| Modificada | Alta (7.5) | 1.2% | — | Opentelemetry ConfiggrpcOpentelemetry ConfighttpOpentelemetry Collector | 5/6/2024 | 17/6/2026 | The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in… | |
| Aplazada | Alta (8.2) | 87% | 💥 PoC | NodejsAINghttp2AI | 9/4/2024 | 17/6/2026 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is… | |
| Modificada | Media (5.3) | 85% | — | Nghttp2Debian LinuxFedoraproject Fedora | 4/4/2024 | 17/6/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 1.3% | — | Envoyproxy EnvoyNghttp2 | 13/7/2023 | 17/6/2026 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy’s HTTP/2 codec may leak a header map and bookkeeping structures upon receiving `RST_STREAM` immediately followed by the `GOAWAY` frames from an upstream server. In nghttp2, cleanup of pending requests due to receipt of the `GOAWAY` frame skips… | |
| Modificada | Alta (7.5) | 3.8% | — | LighttpdFedoraproject Fedora | 6/10/2022 | 17/6/2026 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is… | |
| Modificada | Alta (7.5) | 2.5% | — | LighttpdDebian Linux | 12/9/2022 | 17/6/2026 | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition. | |
| Modificada | Alta (7.5) | 57% | 💥 PoC | Lighttpd | 11/6/2022 | 17/6/2026 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. | |
| Modificada | Media (5.9) | 8.9% | — | LighttpdDebian Linux | 6/1/2022 | 17/6/2026 | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded… | |
| Modificada | Alta (7.5) | 5.3% | — | Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+6 | 3/6/2020 | 17/6/2026 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at… |