Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Aiohttp2/5/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can…
AplazadaMedia (5.5)0.15%—Asus Rt-ac51uAIApache HttpdAI29/4/202417/6/2026
An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service via crafted GET request.
AplazadaAlta (7.1)0.24%—Cutesoft Cute Http File ServerAI19/4/202417/6/2026
CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.
ModificadaMedia (6.1)0.67%—AiohttpFedoraproject Fedora18/4/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are…
AnalizadaMedia (5.3)0.57%—Oracle Http Server16/4/202417/6/2026
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this…
AplazadaAlta (7.5)0.79%—Micrium OS Network Http ServerAI16/4/202417/6/2026
A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially allowing a device crash and Denial of Service.
AplazadaMedia (4.1)0.29%—Opentelemetry Instrumentation.httpAIOpentelemetry Instrumentation.aspnetcoreAI12/4/202417/6/2026
OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled for outgoing http requests and `OpenTelemetry.Instrumentation.AspNetCore`…
AplazadaAlta (8.2)87%💥 PoCNodejsAINghttp2AI9/4/202417/6/2026
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave some data in nghttp2 memory after reset when headers with HTTP/2 CONTINUATION frame are sent to the server and then a TCP connection is…
ModificadaAlta (7.5)91%💥 PoCApache Http ServerFedoraproject FedoraNetapp Ontap4/4/202417/6/2026
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
AnalizadaMedia (6.3)2.9%—Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.
ModificadaAlta (7.3)3.9%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+34/4/202417/6/2026
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
ModificadaMedia (5.3)85%—Nghttp2Debian LinuxFedoraproject Fedora4/4/202417/6/2026
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2…
AplazadaAlta (8.2)83%—Amphp HttpAI3/4/202417/6/2026
amphp/http will collect CONTINUATION frames in an unbounded buffer and will not check a limit until it has received the set END_HEADERS flag, resulting in an OOM crash.
AnalizadaCrítica (9.8)0.82%—Tomphttp Tomp Bare Server21/3/202417/6/2026
TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node package. This flaw potentially exposes the users of the package to manipulation of their web traffic. The impact may vary depending on the…
ModificadaAlta (8.2)0.50%—Iscute Cute Http File Server7/3/20249/7/2026
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.
ModificadaMedia (6.1)0.56%—Http-swagger Project Http-swagger29/2/202417/6/2026
http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests)…
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Uc-http20/2/202417/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaMedia (6.5)1.0%—AiohttpFedoraproject Fedora29/1/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional…
ModificadaAlta (7.5)77%💥 ExploitAiohttpFedoraproject Fedora29/1/202417/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the…
ModificadaAlta (8.1)0.63%—TrilliumTrillium-http24/1/202417/6/2026
Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 and `trillium-client` prior to 0.5.4, insufficient validation of outbound header values may lead to request splitting or response splitting attacks in scenarios where attackers have sufficient…
ModificadaCrítica (9.8)1.1%—Unix4lyfe Darkhttpd22/1/202417/6/2026
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
ModificadaMedia (5.5)0.24%—Unix4lyfe Darkhttpd22/1/202417/6/2026
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
ModificadaCrítica (9.8)1.0%—Dom96 Httpbeast19/1/202417/6/2026
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim component.
ModificadaAlta (7.5)1.3%—Karjasoft Sami Http Server18/1/202417/6/2026
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.5)1.1%—Httpdx Project Httpdx11/1/202417/6/2026
A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST Request Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…
Orbitaley — Vulnerabilidades