Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.43% | — | Haxx Curl | 3/7/2026 | 15/9/2026 | libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later… | |
| Modificada | Alta (7.5) | 0.71% | — | Haxx Curl | 3/7/2026 | 15/9/2026 | An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream… | |
| Modificada | Crítica (9.8) | 0.60% | — | Haxx Curl | 3/7/2026 | 15/9/2026 | A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl… | |
| Modificada | Alta (7.5) | 0.32% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes). | |
| Analizada | Alta (7.5) | 0.60% | 💥 PoC | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on… | |
| Analizada | Alta (7.5) | 0.20% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since 2004 and a single iteration provides no key stretching. | |
| Analizada | Alta (7.5) | 0.51% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json and bypasses Chrome Web Store static security review. It runs on all URLs and immediately hides all page… | |
| Analizada | Alta (7.5) | 0.26% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 hashes that are inadequately obfuscated using a simple Caesar cipher, which can be easily reversed to recover the original hash… | |
| Analizada | Alta (7.3) | 0.30% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data. | |
| Analizada | Alta (7.1) | 0.17% | — | Securly | 3/6/2026 | 22/7/2026 | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension correctly fetch IWF and CIPA data over HTTPS, demonstrating an inconsistent implementation of TLS. | |
| Aplazada | Media (6.9) | 0.48% | — | LibcurlAIMusicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect… | |
| Modificada | Media (5.3) | 0.59% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Proxy-Authorization:` header field meant for `proxyA`, to… | |
| Analizada | Media (5.3) | 0.32% | — | Haxx Curl | 13/5/2026 | 17/6/2026 | When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine. | |
| Modificada | Media (5.3) | 0.51% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances. | |
| Modificada | Alta (7.5) | 0.35% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | |
| Modificada | Media (5.9) | 0.75% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for different URL schemes 2. the first proxy needs credentials 3. the second proxy uses no credentials 4. while using the first… | |
| Modificada | Alta (7.5) | 0.66% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criteria must be met. Due to a logical error in the code, a network… | |
| Modificada | Media (6.5) | 0.51% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a… | |
| Modificada | Media (5.9) | 0.36% | — | Haxx Curl | 13/5/2026 | 15/9/2026 | A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted. | |
| Analizada | Alta (8.6) | 0.45% | 💥 PoC | Lexiforest Curl Cffi | 6/4/2026 | 17/6/2026 | curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges, and follows redirects automatically via the underlying libcurl. Because of this, an attacker-controlled URL can redirect requests to internal services such as cloud metadata endpoints. In addition,… | |
| Aplazada | Alta (8.1) | 0.56% | — | Mikado-themes Curly CoreAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core allows PHP Local File Inclusion.This issue affects Curly Core: from n/a through <= 2.1.6. | |
| Modificada | Alta (7.5) | 0.95% | 💥 PoC | Haxx Curl | 11/3/2026 | 14/9/2026 | When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory. | |
| Modificada | Media (6.5) | 0.45% | — | Haxx Curl | 11/3/2026 | 15/9/2026 | curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a server, even if the new request uses different credentials for the HTTP proxy. The proper behavior is to create or use a separate connection. | |
| Modificada | Media (5.3) | 0.51% | — | Haxx Curl | 11/3/2026 | 15/9/2026 | When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer performs a redirect to a second URL, curl could leak that token to the second hostname under some circumstances. If the hostname that the first request is redirected to has information in the used .netrc file, with either of the `machine`… | |
| Modificada | Media (6.5) | 0.26% | — | Haxx Curl | 11/3/2026 | 15/9/2026 | libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request. libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead. When reusing a connection a range of criterion must first be met.… |