Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1201 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.89% | — | Riverside Http Headers | 15/5/2023 | 17/6/2026 | This HTTP Headers WordPress plugin before 1.18.8 has an import functionality which executes arbitrary SQL on the server, leading to an SQL Injection vulnerability. | |
| Modificada | Alta (8.1) | 1.7% | — | Http\ \Perl | 29/4/2023 | 17/6/2026 | HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates. | |
| Modificada | Media (6.1) | 0.62% | — | Dart Http Server | 10/4/2023 | 17/6/2026 | A vulnerability was found in Dart http_server up to 0.9.5 and classified as problematic. Affected by this issue is the function VirtualDirectory of the file lib/src/virtual_directory.dart of the component Directory Listing Handler. The manipulation of the argument request.uri.path leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 0.72% | — | Ibexa Digital Experience PlatformIbexa Ezplatform-http-cache-fastlyIbexa FastlyIbexa EZ Platform Kernel+1 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | |
| Analizada | Alta (7.5) | 2.1% | — | Apache Http ServerDebian LinuxUnbit Uwsgi | 7/3/2023 | 17/6/2026 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. | |
| Modificada | Crítica (9.8) | 85% | 💥 PoC | Apache Http Server | 7/3/2023 | 17/6/2026 | Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target… | |
| Modificada | Alta (7.5) | 1.1% | — | IBM Http Server | 1/3/2023 | 17/6/2026 | IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296. | |
| Modificada | Media (5.9) | 1.3% | — | GNU Libmicrohttpd | 28/2/2023 | 17/6/2026 | GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data… | |
| Modificada | Alta (7.5) | 4.6% | — | Golang GOGolang HpackGolang Http2 | 28/2/2023 | 17/6/2026 | A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests. | |
| Modificada | Alta (7.8) | 1.1% | — | Is-http2 Project Is-http2 | 1/2/2023 | 17/6/2026 | All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function. | |
| Modificada | Alta (7.5) | 1.6% | — | Http-cache-semantics Project Http-cache-semantics | 31/1/2023 | 17/6/2026 | This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library. | |
| Modificada | Alta (7.5) | 0.68% | — | Paranoidhttp Project Paranoidhttp | 30/1/2023 | 17/6/2026 | Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses. | |
| Modificada | Alta (7.5) | 0.55% | — | Asynchttpclient Project Async-http-client | 18/1/2023 | 17/6/2026 | Versions of Async HTTP Client prior to 1.13.2 are vulnerable to a form of targeted request manipulation called CRLF injection. This vulnerability was the result of insufficient validation of HTTP header field values before sending them to the network. Users are vulnerable if they pass untrusted data into HTTP header… | |
| Modificada | Media (5.3) | 56% | — | Apache Http Server | 17/1/2023 | 17/6/2026 | Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client. | |
| Modificada | Crítica (9) | 1.9% | — | Apache Http Server | 17/1/2023 | 17/6/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions. | |
| Modificada | Alta (7.5) | 3.5% | 💥 PoC | Apache Http Server | 17/1/2023 | 16/6/2026 | A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. | |
| Modificada | Crítica (9.8) | 0.66% | — | Pontifex.http Project Pontifex.http | 15/1/2023 | 17/6/2026 | A vulnerability was found in agy pontifex.http. It has been declared as critical. This vulnerability affects unknown code of the file lib/Http.coffee. The manipulation leads to sql injection. Upgrading to version 0.1.0 is able to address this issue. The name of the patch is e52a758f96861dcef2dabfecb9da191bb2e07761. It… | |
| Modificada | Media (5.3) | 0.84% | — | Typelevel Http4s | 4/1/2023 | 17/6/2026 | Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that… | |
| Modificada | Alta (7.5) | 0.88% | — | Httpserver Project Httpserver | 27/12/2022 | 17/6/2026 | A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The… | |
| Modificada | Alta (7.5) | 0.87% | — | Httpster Project Httpster | 25/12/2022 | 17/6/2026 | A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the patch is… | |
| Modificada | Media (5.3) | 5.8% | 💥 PoC | Golang GOGolang Http2Fedoraproject Fedora | 8/12/2022 | 17/6/2026 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB… | |
| Modificada | Media (6.5) | 2.8% | — | Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,… | |
| Modificada | Alta (7.1) | 1.5% | 💥 Exploit | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow… | |
| Modificada | Crítica (9.8) | 2.0% | — | Silabs Micrium Uc-http | 15/11/2022 | 17/6/2026 | Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request. |