Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1198 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Acme Ultra Mini Httpd7/1/202417/6/2026
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…
ModificadaCrítica (9.8)1.6%—Alekseykurepin Pico Http Server IN C5/1/202417/6/2026
route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.
AnalizadaMedia (5.3)1.3%—Debian LinuxFedoraproject FedoraJnunemaker Httparty4/1/202414/7/2026
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
ModificadaAlta (7.5)0.74%—Hongliuliao Ehttp31/12/202317/6/2026
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
ModificadaAlta (7.5)0.74%—Hongliuliao Ehttp31/12/202317/6/2026
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
ModificadaMedia (4.6)0.29%—Fedirtsapana Simple Http Server Plus27/12/202317/6/2026
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
ModificadaMedia (6.3)0.12%—Fedirtsapana Simple Http ServerFedirtsapana Simple Http Server Plus27/12/202317/6/2026
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS…
ModificadaCrítica (9.8)0.70%—Starnight Micro Http Server25/12/202317/6/2026
In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.
ModificadaMedia (5.4)0.37%—Iscute Cute Http File Server20/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in CuteHttpFileServer v.1.0 and v.2.0 allows attackers to obtain sensitive information via the file upload function in the home page.
ModificadaCrítica (9.8)1.5%💥 PoCStarnight Micro Http Server17/12/202317/6/2026
In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based buffer overflow and potentially remote code execution via a long URI.
ModificadaMedia (5.3)1.1%—Systematica Financial CalculatorSystematica FIX AdapterSystematica Http AdapterSystematica Mssql Messagebus Proxy+230/11/202317/6/2026
Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15),…
ModificadaMedia (5.3)0.88%—Aiohttp30/11/202323/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability only occurs if the attacker can control…
ModificadaMedia (5.3)0.95%—Aiohttp29/11/202323/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method. The vulnerability occurs only if the attacker can…
ModificadaAlta (7.4)0.31%—Httpie16/11/202317/6/2026
Missing SSL certificate validation in HTTPie v3.2.2 allows attackers to eavesdrop on communications between the host and server via a man-in-the-middle attack.
ModificadaMedia (6.5)0.83%—Aiohttp14/11/202317/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Affected versions of aiohttp have a security vulnerability regarding the inconsistent interpretation of the http protocol. HTTP/1.1 is a persistent protocol, if both Content-Length(CL) and Transfer-Encoding(TE) header values are present it…
ModificadaAlta (7.5)0.86%—Aiohttp14/11/202317/6/2026
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parser is only used when AIOHTTP_NO_EXTENSIONS is enabled (or not using a prebuilt wheel). These bugs have been addressed in…
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.5%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.8%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—Silabs Gecko Software Development KITWeston-embedded Cesium NETWeston-embedded Uc-http14/11/202317/6/2026
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
ModificadaMedia (4.9)0.45%—Riverside Http Headers13/11/202317/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Dimitar Ivanov HTTP Headers.This issue affects HTTP Headers: from n/a through 1.18.11.
AnalizadaMedia (5.9)3.0%💥 PoCApache Http ServerFedoraproject FedoraDebian Linux23/10/202317/6/2026
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint…
ModificadaAlta (7.5)71%💥 PoCApache Http Server23/10/202317/6/2026
An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so…
Orbitaley — Vulnerabilidades