Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 162 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.56% | — | Aiohttp | 18/11/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions. If a pure Python version of aiohttp is installed (i.e. without the… | |
| Analizada | Alta (8.7) | 0.59% | — | Aiohttp | 18/11/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError. This was caused by adding an entry to a cache on each request, due to the building of each MatchInfoError producing a… | |
| Analizada | Media (4.3) | 0.47% | — | Sensiolabs Httpclient | 6/11/2024 | 17/6/2026 | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of… | |
| Aplazada | Alta (7.2) | 0.26% | — | Http.zigAI | 30/10/2024 | 17/6/2026 | http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter. | |
| Modificada | Alta (7.7) | 1.0% | — | Chimurai Http-proxy-middleware | 19/10/2024 | 1/8/2026 | Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths. | |
| Analizada | Media (4.8) | 0.65% | — | Aiohttp | 12/8/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to version 3.10.2, static routes which contain files with compressed variants (`.gz` or `.br` extension) are vulnerable to path traversal outside the root directory if those variants are symbolic links.… | |
| Analizada | Alta (8.1) | 0.67% | — | Netty-incubator-codec-ohttp | 18/7/2024 | 17/6/2026 | The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class does not properly validate input values thus giving attackers almost complete control over the HTTP requests constructed from the parsed output. Attackers can abuse several issues individually to… | |
| Modificada | Alta (7.5) | 1.5% | 💥 PoC | Apache Http Server | 18/7/2024 | 17/6/2026 | SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. | |
| Modificada | Media (5.3) | 4.2% | 💥 PoC | Apache Http Server | 18/7/2024 | 17/6/2026 | A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP… | |
| Modificada | Alta (8.8) | 39% | 💥 PoC | Rejetto Http File Server | 4/7/2024 | 17/6/2026 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). | |
| Analizada | Media (6.2) | 0.89% | — | Apache Http ServerNetapp Ontap Tools | 4/7/2024 | 17/6/2026 | A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be… | |
| Aplazada | Alta (7.5) | 1.4% | — | Golang Net/httpAI | 2/7/2024 | 17/6/2026 | The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending… | |
| Modificada | Alta (7.5) | 37% | — | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Modificada | Alta (7.5) | 3.2% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Modificada | Crítica (9.8) | 42% | 💥 PoC | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Analizada | Crítica (9.1) | 100% | ⚠ Explotación activa💥 Exploit | Apache Http ServerNetapp Ontap 9Sonicwall SMA 200 FirmwareSonicwall SMA 210 Firmware+3 | 1/7/2024 | 17/6/2026 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in… | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version… | |
| Analizada | Alta (8.1) | 26% | 💥 Exploit | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Analizada | Alta (7.5) | 69% | 💥 Exploit | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to… | |
| Analizada | Media (5.4) | 1.7% | — | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. | |
| Modificada | Media (5.5) | 0.36% | — | Hashicorp Retryablehttp | 24/6/2024 | 17/6/2026 | go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7. | |
| Aplazada | Media (5.3) | 0.67% | — | LighttpdAI | 17/6/2024 | 17/6/2026 | There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests. | |
| Modificada | Alta (7.5) | 1.2% | — | Opentelemetry ConfiggrpcOpentelemetry ConfighttpOpentelemetry Collector | 5/6/2024 | 17/6/2026 | The OpenTelemetry Collector offers a vendor-agnostic implementation on how to receive, process and export telemetry data. An unsafe decompression vulnerability allows unauthenticated attackers to crash the collector via excessive memory consumption. OTel Collector version 0.102.1 fixes this issue. It is also fixed in… | |
| Modificada | Crítica (9.1) | 0.27% | — | Netty-incubator-codec-ohttp | 4/6/2024 | 17/6/2026 | netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate the appropriate nonce to use with the encryption algorithm. Unfortunately, two separate errors combine which would allow an attacker… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Rejetto Http File Server | 31/5/2024 | 11/8/2026 | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m… |