Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.21% | — | IBM Aspera Http Gateway | 26/9/2025 | 17/6/2026 | IBM Aspera HTTP Gateway 2.0.0 through 2.3.1 stores sensitive information in clear text in easily obtainable files which can be read by an unauthenticated user. | |
| Analizada | Media (6.3) | 0.37% | — | Typelevel Http4s | 23/9/2025 | 17/6/2026 | Http4s is a Scala interface for HTTP services. In versions from 1.0.0-M1 to before 1.0.0-M45 and before 0.23.31, http4s is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section. This vulnerability could enable attackers to bypass front-end servers security controls, launch targeted… | |
| Aplazada | Media (5.4) | 0.33% | — | GO Http.crossoriginprotectionAI | 22/9/2025 | 17/6/2026 | When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections. | |
| Aplazada | Alta (7.1) | 0.13% | — | Presspage Entertainment INC Mavis Https TO Http RedirectionAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection mavis-https-to-http-redirect allows Stored XSS.This issue affects Mavis HTTPS to HTTP Redirection: from n/a through <= 1.4.3. | |
| Aplazada | Baja (3.7) | 0.29% | — | Nghttp2AIPowerdns DnsdistAI | 18/9/2025 | 17/6/2026 | In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources. | |
| Aplazada | Media (5.9) | 0.28% | — | Httpsig-rsAI | 12/9/2025 | 17/6/2026 | httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes anyone who uses HS256 signature verification vulnerable to a timing attack that allows the attacker to forge a signature. Version 0.0.19 fixes the issue. | |
| Aplazada | Crítica (9.1) | 0.26% | — | Opc.httpsAI | 21/8/2025 | 17/6/2026 | A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication. | |
| Aplazada | Alta (8.6) | 0.43% | — | Perl Catalyst Authentication Credential HttpAIPerl Data UuidAI | 11/8/2025 | 17/6/2026 | — | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Miniweb Http ServerAI | 1/8/2025 | 16/6/2026 | An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, followed by a .mof… | |
| Modificada | Media (6.3) | 0.77% | — | Apache Http Server | 23/7/2025 | 17/6/2026 | A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. | |
| Aplazada | Alta (8.7) | 2.1% | — | HttpdasmAI | 23/7/2025 | 16/6/2026 | A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker… | |
| Aplazada | Crítica (9.3) | 4.4% | 💥 Exploit | LighttpdAIDlink Dsp-w110a1AI | 16/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating… | |
| Analizada | Baja (1.7) | 0.33% | — | Aiohttp | 14/7/2025 | 17/6/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trailer sections of an HTTP request. If a pure Python version of aiohttp is installed (i.e. without the usual C extensions)… | |
| Analizada | Alta (7.5) | 0.55% | — | Yhirose Cpp-httplib | 10/7/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is… | |
| Analizada | Media (6.3) | 0.49% | — | Yhirose Cpp-httplib | 10/7/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629. | |
| Aplazada | Crítica (9.3) | 1.7% | 💥 Exploit | Easy File Sharing Http ServerAI | 10/7/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in Easy File Sharing HTTP Server version 7.2. The flaw is triggered when a crafted POST request is sent to the /sendemail.ghp endpoint containing an overly long Email parameter. The application fails to properly validate the length of this field, resulting in a memory… | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Apache Http Server | 10/7/2025 | 17/6/2026 | Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue. | |
| Modificada | Alta (7.4) | 0.59% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to… | |
| Modificada | Alta (7.5) | 1.3% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse proxy is configured for an HTTP/2 backend, with ProxyPreserveHost set to "on". | |
| Modificada | Crítica (9.1) | 1.0% | 💥 PoC | Apache Http Server | 10/7/2025 | 17/6/2026 | In some mod_ssl configurations on Apache HTTP Server 2.4.35 through to 2.4.63, an access control bypass by trusted clients is possible using TLS 1.3 session resumption. Configurations are affected when mod_ssl is configured for multiple virtual hosts, with each restricted to a different set of trusted client… | |
| Modificada | Alta (7.5) | 0.77% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. In a logging configuration where CustomLog is used with "%{varname}x" or "%{varname}c" to log variables provided by… | |
| Modificada | Alta (7.5) | 1.2% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63. Note: The Apache HTTP Server Project will be… | |
| Modificada | Alta (7.5) | 0.87% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are… | |
| Modificada | Alta (7.5) | 0.79% | — | Apache Http Server | 10/7/2025 | 17/6/2026 | HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not… | |
| Aplazada | Alta (8.7) | 0.43% | — | EspasynchttpserverAI | 27/6/2025 | 17/6/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows… |