Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.6) | 0.50% | — | Aiohttp | 1/4/2026 | 17/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the static resource handler may expose information about a NTLMv2 remote path. This issue has been patched in version 3.13.4. | |
| Analizada | Baja (2.7) | 0.40% | — | Aiohttp | 1/4/2026 | 17/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4. | |
| Analizada | Baja (2.7) | 0.61% | — | Aiohttp | 1/4/2026 | 17/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an unbounded DNS cache could result in excessive memory usage possibly resulting in a DoS situation. This issue has been patched in version 3.13.4. | |
| Analizada | Media (6.9) | 0.44% | — | Aiohttp | 1/4/2026 | 17/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, insufficient restrictions in header/trailer handling could cause uncapped memory usage. This issue has been patched in version 3.13.4. | |
| Analizada | Media (6.5) | 0.28% | — | Yhirose Cpp-httplib | 31/3/2026 | 24/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.40.0, cpp-httplib is vulnerable to HTTP Request Smuggling. The server's static file handler serves GET responses without consuming the request body. On HTTP/1.1 keep-alive connections, the unread body bytes remain on… | |
| Modificada | Crítica (9.8) | 0.71% | — | Ktat Http\ | 28/3/2026 | 29/6/2026 | HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults to using HTTP::Session::ID::SHA1 to generate session ids using a SHA-1 hash seeded with the built-in rand function, the high resolution epoch time, and the PID. The PID will come from a small set of… | |
| Analizada | Alta (7.4) | 0.35% | — | Yhirose Cpp-httplib | 27/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP client forwards stored Basic Auth, Bearer Token, and Digest Auth credentials to arbitrary hosts when following cross-origin HTTP redirects (301/302/307/308). A malicious or compromised server can… | |
| Analizada | Alta (8.5) | 0.15% | — | Smallsrv Small Http Server | 26/3/2026 | 17/6/2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing… | |
| Analizada | Alta (8.7) | 0.61% | — | Smallsrv Small Http Server | 26/3/2026 | 17/6/2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server. | |
| Modificada | Alta (7.5) | 0.89% | — | Nghttp2 | 18/3/2026 | 15/7/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the application. They might be called… | |
| Analizada | Alta (8.1) | 0.25% | — | Yhirose Cpp-httplib | 16/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib client is configured with a proxy and set_follow_location(true), any HTTPS redirect it follows will have TLS certificate and hostname verification silently disabled on the new connection. The client… | |
| Analizada | Alta (7.5) | 0.55% | — | Yhirose Cpp-httplib | 11/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.), the library calls std::stoull() directly on the Content-Length header value received from the server with no input… | |
| Analizada | Alta (8.8) | 0.71% | — | Apache Airflow Providers Http | 9/3/2026 | 17/6/2026 | A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likelihood of it making any damage is low. You should upgrade to… | |
| Analizada | Media (5.9) | 0.61% | — | Yhirose Cpp-httplib | 7/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib uses std::regex (libstdc++) to parse RFC 5987 encoded filename* values in multipart Content-Disposition headers. The regex engine in libstdc++ implements backtracking via deep recursion, consuming one… | |
| Analizada | Alta (7.5) | 0.62% | — | Yhirose Cpp-httplib | 4/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, cpp-httplib (httplib.h) does not enforce Server::set_payload_max_length() on the decompressed request body when using HandlerWithContentReader (streaming ContentReader) with Content-Encoding: gzip (or other supported… | |
| Analizada | Media (5.3) | 0.43% | — | Yhirose Cpp-httplib | 4/3/2026 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.35.0, when a request handler throws a C++ exception and the application has not registered a custom exception handler via set_exception_handler(), the library catches the exception and writes its message directly into the HTTP… | |
| Analizada | Media (6.5) | 0.41% | — | Tokuhirom Http\ | 27/2/2026 | 17/6/2026 | HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in… | |
| Analizada | Media (6.5) | 0.49% | — | Tokuhirom Http\ | 27/2/2026 | 17/6/2026 | HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP::Session2 session id generator returns a SHA-1 hash seeded with the built-in rand function, the epoch time, and the PID. The PID will come from a small set of numbers, and the epoch time may be… | |
| Analizada | Alta (7.5) | 0.25% | — | Junkurihara Httpsig-hyper | 19/2/2026 | 17/6/2026 | httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to misuse of Rust's `matches!` macro. Specifically, the comparison `if matches!(digest, _expected_digest)` treated… | |
| Aplazada | Alta (8.7) | 0.80% | — | Crystal Live Http ServerAI | 18/2/2026 | 17/6/2026 | Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files. | |
| Aplazada | Media (5.5) | 2.2% | — | Jishi Node-sonos-http-apiAI | 17/2/2026 | 17/6/2026 | A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is the function Promise of the file lib/tts-providers/mac-os.js of the component TTS Provider. This manipulation of the argument phrase causes os command injection. It is possible to initiate the attack… | |
| Aplazada | Crítica (9.1) | 0.30% | — | Xiaomi Galaxy FDS SDK AndroidAIApache HttpclientAI | 12/2/2026 | 14/7/2026 | Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and prior disable TLS hostname verification when HTTPS is enabled (the default configuration). In GalaxyFDSClientImpl.createHttpClient(), the SDK configures Apache HttpClient with SSLSocketFactory.ALLOW_ALL_HOSTNAME_VERIFIER, which accepts any valid… | |
| Aplazada | Crítica (9.8) | 0.69% | — | LighttpdAI | 9/2/2026 | 17/6/2026 | An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections. | |
| Aplazada | Media (6.9) | 0.60% | — | Crystal Shard Http-protectionAI | 30/1/2026 | 17/6/2026 | Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized… | |
| Analizada | Alta (7.5) | 0.30% | — | Bmeme Http Client Manager | 28/1/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsing.This issue affects HTTP Client Manager: from 0.0.0 before 9.3.13, from 10.0.0 before 10.0.2, from 11.0.0 before 11.0.1. |