Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 16% | — | Apache Http ServerCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server+1 | 8/3/2015 | 17/6/2026 | The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function. | |
| Modificada | Media (4.3) | 22% | — | Apache Http ServerCanonical Ubuntu LinuxFedoraproject FedoraOracle Enterprise Manager OPS Center | 29/12/2014 | 17/6/2026 | mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic… | |
| Modificada | Media (5) | 11% | — | Apple MAC OS XApple OS X ServerApache Http ServerCanonical Ubuntu Linux | 15/12/2014 | 17/6/2026 | The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers. | |
| Modificada | Media (5) | 14% | — | Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 10/10/2014 | 17/6/2026 | The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header. | |
| Modificada | Media (5) | 16% | — | Apache Http Server | 20/7/2014 | 17/6/2026 | Memory leak in the winnt_accept function in server/mpm/winnt/child.c in the WinNT MPM in the Apache HTTP Server 2.4.x before 2.4.10 on Windows, when the default AcceptFilter is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted requests. | |
| Modificada | Media (5) | 44% | — | Apache Http Server | 20/7/2014 | 17/6/2026 | The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor. | |
| Modificada | Media (6.8) | 86% | 💥 Exploit | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Enterprise Manager OPS Center+2 | 20/7/2014 | 17/6/2026 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the… | |
| Modificada | Media (4.3) | 37% | — | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application Platform | 20/7/2014 | 17/6/2026 | The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data that decompresses to a much larger size. | |
| Modificada | Media (4.3) | 36% | — | Apache Http ServerApple MAC OS X | 20/7/2014 | 17/6/2026 | The mod_proxy module in the Apache HTTP Server 2.4.x before 2.4.10, when a reverse proxy is enabled, allows remote attackers to cause a denial of service (child-process crash) via a crafted HTTP Connection header. | |
| Modificada | Media (4.3) | 12% | — | Apache Http Server | 20/7/2014 | 16/6/2026 | The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, when a caching forward proxy is enabled, allows remote HTTP servers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger a missing hostname value. | |
| Modificada | Media (5) | 53% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+11 | 15/4/2014 | 16/6/2026 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." | |
| Modificada | Media (5) | 27% | — | Apache Http ServerOracle Http ServerOracle Secure Global DesktopCanonical Ubuntu Linux | 18/3/2014 | 17/6/2026 | The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation. | |
| Modificada | Media (5) | 27% | — | Apache Http ServerOracle Http ServerCanonical Ubuntu Linux | 18/3/2014 | 17/6/2026 | The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request. | |
| Modificada | Alta (7.8) | 2.5% | — | Gummybearstudios FTP Drive + Http Server | 25/11/2013 | 16/6/2026 | Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request. | |
| Modificada | Alta (7.5) | 14% | — | Apache Http Server | 23/7/2013 | 16/6/2026 | mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds with save operations for a session without considering the dirty flag and the requirement for a new session ID, which has unspecified impact and remote attack vectors. | |
| Modificada | Media (4.3) | 29% | — | Apache Http ServerRedhat Jboss Enterprise Application PlatformRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+5 | 10/7/2013 | 16/6/2026 | mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML… | |
| Modificada | Media (5.1) | 25% | — | Apache Http ServerRedhat Jboss Enterprise Application PlatformOracle Http ServerRedhat Enterprise Linux Desktop+6 | 10/6/2013 | 16/6/2026 | mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5.9) | 84% | — | Oracle Communications Application Session ControllerOracle Http ServerOracle Integrated Lights OUT Manager FirmwareFujitsu Sparc Enterprise M3000 Firmware+12 | 15/3/2013 | 16/6/2026 | The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext. | |
| Modificada | Media (4.3) | 23% | — | Apache Http Server | 26/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the balancer_handler function in the manager interface in mod_proxy_balancer.c in the mod_proxy_balancer module in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Modificada | Media (4.3) | 23% | — | Apache Http Server | 26/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status… | |
| Modificada | Alta (10) | 4.4% | — | IBM Http ServerIBM Websphere Application Server | 20/12/2012 | 16/6/2026 | Unspecified vulnerability in the IBM HTTP Server component 5.3 in IBM WebSphere Application Server (WAS) for z/OS allows remote attackers to execute arbitrary commands via unknown vectors. | |
| Modificada | Media (5) | 17% | — | Apache Http Server | 30/11/2012 | 16/6/2026 | The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request. | |
| Modificada | Media (4.3) | 9.6% | — | Apache Http Server | 22/8/2012 | 16/6/2026 | The proxy functionality in (1) mod_proxy_ajp.c in the mod_proxy_ajp module and (2) mod_proxy_http.c in the mod_proxy_http module in the Apache HTTP Server 2.4.x before 2.4.3 does not properly determine the situations that require closing a back-end connection, which allows remote attackers to obtain sensitive… | |
| Modificada | Baja (2.6) | 23% | — | Apache Http Server | 22/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not… | |
| Modificada | Media (4.3) | 3.3% | — | Trustwave ModsecurityOpensuseDebian LinuxOracle Http Server | 22/7/2012 | 16/6/2026 | ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as… |