Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.49%—Yhirose Cpp-httplib26/6/202517/6/2026
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the library does not limit the number of headers, and the memory associated with the headers will not be released when the connection is disconnected. This leads to…
AplazadaAlta (7.7)0.43%—Http JLAIUris JLAI25/6/202517/6/2026
HTTP.jl provides HTTP client and server functionality for Julia, and URIs.jl parses and works with Uniform Resource Identifiers (URIs). URIs.jl prior to version 1.6.0 and HTTP.jl prior to version 1.10.17 allows the construction of URIs containing CR/LF characters. If user input was not otherwise escaped or protected,…
AplazadaMedia (6.5)0.51%💥 PoCNodejsAILlhttpAI19/5/202517/6/2026
A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers to bypass proxy-based access controls and submit unauthorized requests. The issue was resolved by upgrading `llhttp` to…
AplazadaMedia (5.4)0.29%—Pgina ForkAIPgina HttpauthAI15/5/202517/6/2026
The HttpAuth plugin in pGina.Fork through 3.9.9.12 allows authentication bypass when an adversary controls DNS resolution for pginaloginserver.
AnalizadaAlta (7.5)0.66%—Cpp-httplib Project Cpp-httplib6/5/202517/6/2026
cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked request without…
ModificadaAlta (7.5)1.6%—Apache Http ServerRedhat Enterprise LinuxDebian Linux29/4/202529/6/2026
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The server crashes consistently, affecting availability.
AplazadaAlta (7.5)2.3%—Nghttp2AIH2OAIPowerdns DnsdistAI29/4/202517/6/2026
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing a denial of service. The remedy is: upgrade to the patched 1.9.9 version. A workaround is to…
AplazadaAlta (7.7)0.29%—LighttpdAI25/4/202517/6/2026
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted…
AnalizadaAlta (7.5)0.95%—Apache HttpclientNetapp Ontap Tools24/4/202517/6/2026
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
AplazadaMedia (5.4)0.33%—Pear Http Request2AI17/4/202517/6/2026
In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.
AnalizadaMedia (5.3)0.47%—Chimurai Http-proxy-middleware15/4/202517/6/2026
In http-proxy-middleware before 2.0.9 and 3.x before 3.0.5, fixRequestBody proceeds even if bodyParser has failed.
AnalizadaMedia (5.3)0.46%—Chimurai Http-proxy-middleware15/4/202517/6/2026
In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.
AplazadaCrítica (9.1)0.81%—Golang Net/httpAI8/4/202517/6/2026
The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.
AplazadaAlta (7.1)0.39%—Trendnet Ti-g102iAILighttpdAI30/3/202517/6/2026
A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be done within the…
AplazadaMedia (5.3)0.44%—AtophttpdAI26/3/202517/6/2026
httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.
AnalizadaMedia (5.6)0.57%—Apache Felix Http Webconsole Plugin12/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin. This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
AnalizadaAlta (7.5)0.36%—The-guild Graphql Mesh CLIThe-guild Graphql Mesh Http20/2/202517/6/2026
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. Missing check vulnerability in the static file handler allows any client to access the…
AplazadaAlta (7)0.25%—AiohttpAIAiohttp SessionAIHome-assistant Home Assistant CoreAI18/2/202517/6/2026
Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are subject to a potential man-in-the-middle attacks due to missing SSL certificate verification in the project codebase and used third-party libraries. In the past, `aiohttp-session`/`request` had the…
AnalizadaMedia (6.9)0.41%—Yhirose Cpp-httplib4/2/202517/6/2026
cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more.
AnalizadaMedia (5.3)0.51%—Oracle Http Server21/1/202517/6/2026
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability…
AplazadaAlta (7.1)0.17%—Eyga.net Http TO Https Link ChangerAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4.
AnalizadaAlta (7.3)0.32%—Basic Http Authentication Project Basic Http Authentication9/1/202517/6/2026
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.
AplazadaCrítica (9.8)1.9%💥 PoCHttp4kAI12/12/202417/6/2026
http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side…
AplazadaAlta (7.4)0.83%—Quarkus-httpAI12/12/20244/8/2026
A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading to unauthorized data access or…
AplazadaCrítica (9.2)0.64%—AsynchttpclientAI2/12/202417/6/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name…
Orbitaley — Vulnerabilidades