Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1198 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Aiohttp | 2/5/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can… | |
| Aplazada | Media (5.5) | 0.15% | — | Asus Rt-ac51uAIApache HttpdAI | 29/4/2024 | 17/6/2026 | An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request. | |
| Aplazada | Alta (7.1) | 0.24% | — | Cutesoft Cute Http File ServerAI | 19/4/2024 | 17/6/2026 | CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information. | |
| Modificada | Media (6.1) | 0.67% | — | AiohttpFedoraproject Fedora | 18/4/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are… | |
| Analizada | Media (5.3) | 0.57% | — | Oracle Http Server | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this… | |
| Aplazada | Alta (7.5) | 0.79% | — | Micrium OS Network Http ServerAI | 16/4/2024 | 17/6/2026 | A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially allowing a device crash and Denial of Service. | |
| Aplazada | Media (4.1) | 0.29% | — | Opentelemetry Instrumentation.httpAIOpentelemetry Instrumentation.aspnetcoreAI | 12/4/2024 | 17/6/2026 | OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled for outgoing http requests and `OpenTelemetry.Instrumentation.AspNetCore`… | |
| Aplazada | Alta (8.2) | 87% | 💥 PoC | NodejsAINghttp2AI | 9/4/2024 | 17/6/2026 | An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is… | |
| Modificada | Alta (7.5) | 91% | 💥 PoC | Apache Http ServerFedoraproject FedoraNetapp Ontap | 4/4/2024 | 17/6/2026 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. | |
| Analizada | Media (6.3) | 2.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| Modificada | Alta (7.3) | 3.9% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| Modificada | Media (5.3) | 85% | — | Nghttp2Debian LinuxFedoraproject Fedora | 4/4/2024 | 17/6/2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2… | |
| Aplazada | Alta (8.2) | 83% | — | Amphp HttpAI | 3/4/2024 | 17/6/2026 | amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash. | |
| Analizada | Crítica (9.8) | 0.82% | — | Tomphttp Tomp Bare Server | 21/3/2024 | 17/6/2026 | TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node package. This flaw potentially exposes the users of the package to manipulation of their web traffic. The impact may vary depending on the… | |
| Modificada | Alta (8.2) | 0.50% | — | Iscute Cute Http File Server | 7/3/2024 | 9/7/2026 | An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component. | |
| Modificada | Media (6.1) | 0.56% | — | Http-swagger Project Http-swagger | 29/2/2024 | 17/6/2026 | http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests)… | |
| Modificada | Crítica (9.8) | 1.7% | — | Silabs Gecko Software Development KITWeston-embedded Uc-http | 20/2/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.0% | — | AiohttpFedoraproject Fedora | 29/1/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional… | |
| Modificada | Alta (7.5) | 77% | 💥 Exploit | AiohttpFedoraproject Fedora | 29/1/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the… | |
| Modificada | Alta (8.1) | 0.63% | — | TrilliumTrillium-http | 24/1/2024 | 17/6/2026 | Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 and `trillium-client` prior to 0.5.4, insufficient validation of outbound header values may lead to request splitting or response splitting attacks in scenarios where attackers have sufficient… | |
| Modificada | Crítica (9.8) | 1.1% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel. | |
| Modificada | Media (5.5) | 0.24% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. | |
| Modificada | Crítica (9.8) | 1.0% | — | Dom96 Httpbeast | 19/1/2024 | 17/6/2026 | An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim component. | |
| Modificada | Alta (7.5) | 1.3% | — | Karjasoft Sami Http Server | 18/1/2024 | 17/6/2026 | A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.5) | 1.1% | — | Httpdx Project Httpdx | 11/1/2024 | 17/6/2026 | A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST Request Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… |