Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1201 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.89%—Riverside Http Headers15/5/202317/6/2026
This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability.
ModificadaAlta (8.1)1.7%—Http\ \Perl29/4/202317/6/2026
HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
ModificadaMedia (6.1)0.62%—Dart Http Server10/4/202317/6/2026
A vulnerability was found in Dart http_server up to 0.9.5 and classified as problematic. Affected by this issue is the function VirtualDirectory of the file lib/src/virtual_directory.dart of the component Directory Listing Handler. The manipulation of the argument request.uri.path leads to cross site scripting. The…
ModificadaCrítica (9.8)0.72%—Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+112/3/202317/6/2026
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
AnalizadaAlta (7.5)2.1%—Apache Http ServerDebian LinuxUnbit Uwsgi7/3/202317/6/2026
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.
ModificadaCrítica (9.8)85%💥 PoCApache Http Server7/3/202317/6/2026
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target…
ModificadaAlta (7.5)1.1%—IBM Http Server1/3/202317/6/2026
IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296.
ModificadaMedia (5.9)1.3%—GNU Libmicrohttpd28/2/202317/6/2026
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data…
ModificadaAlta (7.5)4.6%—Golang GOGolang HpackGolang Http228/2/202317/6/2026
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
ModificadaAlta (7.8)1.1%—Is-http2 Project Is-http21/2/202317/6/2026
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.
ModificadaAlta (7.5)1.6%—Http-cache-semantics Project Http-cache-semantics31/1/202317/6/2026
This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.
ModificadaAlta (7.5)0.68%—Paranoidhttp Project Paranoidhttp30/1/202317/6/2026
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.
ModificadaAlta (7.5)0.55%—Asynchttpclient Project Async-http-client18/1/202317/6/2026
Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header…
ModificadaMedia (5.3)56%—Apache Http Server17/1/202317/6/2026
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
ModificadaCrítica (9)1.9%—Apache Http Server17/1/202317/6/2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
ModificadaAlta (7.5)3.5%💥 PoCApache Http Server17/1/202316/6/2026
A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier.
ModificadaCrítica (9.8)0.66%—Pontifex.http Project Pontifex.http15/1/202317/6/2026
A vulnerability was found in agy pontifex.http. It has been declared as critical. This vulnerability affects unknown code of the file lib/Http.coffee. The manipulation leads to sql injection. Upgrading to version 0.1.0 is able to address this issue. The name of the patch is e52a758f96861dcef2dabfecb9da191bb2e07761. It…
ModificadaMedia (5.3)0.84%—Typelevel Http4s4/1/202317/6/2026
Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that…
ModificadaAlta (7.5)0.88%—Httpserver Project Httpserver27/12/202217/6/2026
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The…
ModificadaAlta (7.5)0.87%—Httpster Project Httpster25/12/202217/6/2026
A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the patch is…
ModificadaMedia (5.3)5.8%💥 PoCGolang GOGolang Http2Fedoraproject Fedora8/12/202217/6/2026
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB…
ModificadaMedia (6.5)2.8%—Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux5/12/202217/6/2026
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
ModificadaCrítica (9.8)1.2%—Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment4/12/202217/6/2026
Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,…
ModificadaAlta (7.1)1.5%💥 ExploitProxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment4/12/202217/6/2026
A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow…
ModificadaCrítica (9.8)2.0%—Silabs Micrium Uc-http15/11/202217/6/2026
Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.