Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2756▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 162 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

1198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)0.56%—Aiohttp18/11/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions. If a pure Python version of aiohttp is installed (i.e. without the…
AnalizadaAlta (8.7)0.59%—Aiohttp18/11/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError. This was caused by adding an entry to a cache on each request, due to the building of each MatchInfoError producing a…
AnalizadaMedia (4.3)0.47%—Sensiolabs Httpclient6/11/202417/6/2026
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of…
AplazadaAlta (7.2)0.26%—Http.zigAI30/10/202417/6/2026
http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.
ModificadaAlta (7.7)1.0%—Chimurai Http-proxy-middleware19/10/20241/8/2026
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
AnalizadaMedia (4.8)0.65%—Aiohttp12/8/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root directory if those variants are symbolic links.…
AnalizadaAlta (8.1)0.67%—Netty-incubator-codec-ohttp18/7/202417/6/2026
The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class does not properly validate input values thus giving attackers almost complete control over the HTTP requests constructed from the parsed output. Attackers can abuse several issues individually to…
ModificadaAlta (7.5)1.5%💥 PoCApache Http Server18/7/202417/6/2026
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
ModificadaMedia (5.3)4.2%💥 PoCApache Http Server18/7/202417/6/2026
A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP…
ModificadaAlta (8.8)39%💥 PoCRejetto Http File Server4/7/202417/6/2026
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
AnalizadaMedia (6.2)0.89%—Apache Http ServerNetapp Ontap Tools4/7/202417/6/2026
A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be…
AplazadaAlta (7.5)1.4%—Golang Net/httpAI2/7/202417/6/2026
The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending…
ModificadaAlta (7.5)37%—Apache Http ServerNetapp Ontap1/7/202417/6/2026
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
ModificadaAlta (7.5)3.2%—Apache Http ServerNetapp Clustered Data Ontap1/7/202417/6/2026
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
ModificadaCrítica (9.8)42%💥 PoCApache Http ServerNetapp Clustered Data Ontap1/7/202417/6/2026
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
AnalizadaCrítica (9.1)100%⚠ Explotación activa💥 ExploitApache Http ServerNetapp Ontap 9Sonicwall SMA 200 FirmwareSonicwall SMA 210 Firmware+31/7/202417/6/2026
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in…
ModificadaCrítica (9.8)2.5%—Apache Http ServerNetapp Clustered Data Ontap1/7/202417/6/2026
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version…
AnalizadaAlta (8.1)26%💥 ExploitApache Http ServerNetapp Ontap1/7/202417/6/2026
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
AnalizadaAlta (7.5)69%💥 ExploitApache Http ServerNetapp Ontap1/7/202417/6/2026
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to…
AnalizadaMedia (5.4)1.7%—Apache Http ServerNetapp Ontap1/7/202417/6/2026
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
ModificadaMedia (5.5)0.36%—Hashicorp Retryablehttp24/6/202417/6/2026
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.
AplazadaMedia (5.3)0.67%—LighttpdAI17/6/202417/6/2026
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.
ModificadaAlta (7.5)1.2%—Opentelemetry ConfiggrpcOpentelemetry ConfighttpOpentelemetry Collector5/6/202417/6/2026
The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in…
ModificadaCrítica (9.1)0.27%—Netty-incubator-codec-ohttp4/6/202417/6/2026
netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitRejetto Http File Server31/5/202411/8/2026
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m…
Orbitaley — Vulnerabilidades