Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

552 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)14%—Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+225/10/200516/6/2026
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
ModificadaAlta (10)31%—Apache Http ServerDebian LinuxCanonical Ubuntu Linux6/9/200516/6/2026
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
ModificadaMedia (5)11%—Apache Http Server30/8/200516/6/2026
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
ModificadaMedia (5)8.4%—Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+15/8/200516/6/2026
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.
ModificadaMedia (4.3)20%—Apache Http ServerDebian Linux5/7/200516/6/2026
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes…
ModificadaAlta (7.5)29%💥 ExploitApache Http Server2/5/200516/6/2026
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI…
ModificadaMedia (5)1.8%—Sami Http Server2/5/200516/6/2026
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
ModificadaMedia (5)3.1%—Sami Http Server2/5/200516/6/2026
Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.
ModificadaMedia (5)55%💥 ExploitApache Http Server9/2/200516/6/2026
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
ModificadaAlta (7.8)4.8%💥 ExploitApache Http ServerOpenpkgHp-uxSlackware Linux+29/2/200516/6/2026
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
ModificadaAlta (7.2)0.60%—Apache Http Server31/12/200416/6/2026
Apache HTTP Server 2.0.47 and earlier allows local users to bypass .htaccess file restrictions, as specified in httpd.conf with directives such as Deny From All, by using an ErrorDocument directive. NOTE: the vendor has disputed this issue, since the .htaccess mechanism is only intended to restrict external web…
ModificadaMedia (5)1.4%—Mbedthis Software Mbedthis Appweb Http Server31/12/200416/6/2026
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) trailing space in an HTTP request.
ModificadaMedia (5)1.8%—Jetty Http Server31/12/200416/6/2026
HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.
ModificadaAlta (7.5)2.3%—HP SSL Http Server31/12/200416/6/2026
The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.
ModificadaAlta (7.5)72%💥 ExploitMinishare Minimal Http Server31/12/200416/6/2026
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaMedia (5)1.2%—Mbedthis Software Mbedthis Appweb Http Server31/12/200416/6/2026
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
ModificadaAlta (7.5)2.4%—CA Unicenter WEB Services Distributed ManagementIBM Trading Partner InterchangeJetty Http Server31/12/200416/6/2026
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (6.8)58%💥 ExploitOracle Http Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
ModificadaAlta (7.5)7.6%—Apache Http Server31/12/200416/6/2026
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
ModificadaCrítica (9.8)2.7%—Mbedthis Appweb Http Server31/12/200416/6/2026
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
ModificadaBaja (2.1)0.55%—Apache Http Server31/12/200416/6/2026
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
ModificadaMedia (5)1.7%—Mbedthis Software Mbedthis Appweb Http Server31/12/200416/6/2026
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.
ModificadaMedia (5)3.9%—Apache Http ServerIBM Http Server23/11/200416/6/2026
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information.
ModificadaMedia (5)3.2%💥 ExploitGweb Http Server23/11/200416/6/2026
Directory traversal vulnerability in GWeb HTTP Server 0.6 allows remote attackers to view arbitrary files via a .. (dot dot) in the URL.
ModificadaAlta (10)7.6%💥 ExploitKarjasoft Sami Http Server23/11/200416/6/2026
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
Orbitaley — Vulnerabilidades