Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.5% | 💥 PoC | Apache Http Server | 17/1/2023 | 16/6/2026 | A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash. This issue affects Apache HTTP Server 2.4.54 and earlier. | |
| Modificada | Crítica (9.8) | 0.66% | — | Pontifex.http Project Pontifex.http | 15/1/2023 | 17/6/2026 | A vulnerability was found in agy pontifex.http. It has been declared as critical. This vulnerability affects unknown code of the file lib/Http.coffee. The manipulation leads to sql injection. Upgrading to version 0.1.0 is able to address this issue. The name of the patch is e52a758f96861dcef2dabfecb9da191bb2e07761. It… | |
| Modificada | Media (5.3) | 0.84% | — | Typelevel Http4s | 4/1/2023 | 17/6/2026 | Http4s is a Scala interface for HTTP services. Starting with version 0.1.0 and prior to versions 0.21.34, 0.22.15, 0.23.17, and 1.0.0-M38, the `User-Agent` and `Server` header parsers are susceptible to a fatal error on certain inputs. In http4s, modeled headers are lazily parsed, so this only applies to services that… | |
| Modificada | Alta (7.5) | 0.88% | — | Httpserver Project Httpserver | 27/12/2022 | 17/6/2026 | A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The… | |
| Modificada | Alta (7.5) | 0.87% | — | Httpster Project Httpster | 25/12/2022 | 17/6/2026 | A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the patch is… | |
| Modificada | Media (5.3) | 5.8% | 💥 PoC | Golang GOGolang Http2Fedoraproject Fedora | 8/12/2022 | 17/6/2026 | An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB… | |
| Modificada | Media (6.5) | 2.8% | — | Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| Modificada | Crítica (9.8) | 1.2% | — | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway,… | |
| Modificada | Alta (7.1) | 1.5% | 💥 Exploit | Proxmox Mail GatewayProxmox PVE Http ServerProxmox Virtual Environment | 4/12/2022 | 17/6/2026 | A response-header CRLF injection vulnerability in the Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) web interface allows a remote attacker to set cookies for a victim's browser that are longer than the server expects, causing a client-side DoS. This affects Chromium-based browsers because they allow… | |
| Modificada | Crítica (9.8) | 2.0% | — | Silabs Micrium Uc-http | 15/11/2022 | 17/6/2026 | Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request. | |
| Modificada | Media (6.1) | 0.70% | — | Facetwp LOG Http Requests | 28/10/2022 | 17/6/2026 | The Log HTTP Requests plugin for WordPress is vulnerable to Stored Cross-Site Scripting via logged HTTP requests in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers who can trick a site's administrator into performing… | |
| Modificada | Alta (7.1) | 0.71% | — | Oracle Http Server | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful… | |
| Modificada | Alta (7.5) | 3.8% | — | LighttpdFedoraproject Fedora | 6/10/2022 | 17/6/2026 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is… | |
| Modificada | Media (6.5) | 0.66% | — | Jenkins SCM Httpclient | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.46% | — | Jenkins SCM Httpclient | 21/9/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 2.5% | — | LighttpdDebian Linux | 12/9/2022 | 17/6/2026 | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition. | |
| Modificada | Media (5.3) | 1.0% | — | Reactphp Http | 6/9/2022 | 17/6/2026 | ReactPHP HTTP is a streaming HTTP client and server implementation for ReactPHP. In ReactPHP's HTTP server component versions starting with 0.7.0 and prior to 1.7.0, when ReactPHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like `__Host-` and… | |
| Modificada | Media (4.8) | 0.56% | — | Redhat Jboss Core Services Httpd | 26/8/2022 | 17/6/2026 | A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this… | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Inglorion MuhttpdArris Nvg443 FirmwareArris Nvg599 FirmwareArris Nvg589 Firmware+3 | 4/8/2022 | 17/6/2026 | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and… | |
| Modificada | Media (6.5) | 0.84% | — | Jenkins Http Request | 27/7/2022 | 17/6/2026 | Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (6.5) | 70% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 82% | — | LlhttpNodejs Node.jsDebian LinuxStormshield Management Center | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Media (6.5) | 46% | — | LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+2 | 14/7/2022 | 17/6/2026 | The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). | |
| Modificada | Crítica (9.8) | 1.00% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 0.51% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. |