Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel. | |
| Modificada | Media (5.5) | 0.24% | — | Unix4lyfe Darkhttpd | 22/1/2024 | 17/6/2026 | darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. | |
| Modificada | Alta (7.5) | 1.1% | — | Httpdx Project Httpdx | 11/1/2024 | 17/6/2026 | A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST Request Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.5) | 1.4% | — | Acme Ultra Mini Httpd | 7/1/2024 | 17/6/2026 | A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.9) | 1.3% | — | GNU Libmicrohttpd | 28/2/2023 | 17/6/2026 | GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data… | |
| Modificada | Alta (7.5) | 3.8% | — | LighttpdFedoraproject Fedora | 6/10/2022 | 17/6/2026 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is… | |
| Modificada | Alta (7.5) | 2.5% | — | LighttpdDebian Linux | 12/9/2022 | 17/6/2026 | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition. | |
| Modificada | Media (4.8) | 0.56% | — | Redhat Jboss Core Services Httpd | 26/8/2022 | 17/6/2026 | A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this… | |
| Modificada | Alta (7.5) | 17% | — | Inglorion MuhttpdArris Nvg443 FirmwareArris Nvg599 FirmwareArris Nvg589 Firmware+3 | 4/8/2022 | 17/6/2026 | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and… | |
| Modificada | Alta (7.5) | 57% | — | Lighttpd | 11/6/2022 | 17/6/2026 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. | |
| Modificada | Media (5.5) | 0.30% | — | Nanohttpd | 1/5/2022 | 17/6/2026 | This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP request, the body of the request is written to a RandomAccessFile when the it is larger than 1024 bytes. This file is created with insecure permissions that allow its contents to be viewed by all users… | |
| Modificada | Alta (7.5) | 1.5% | — | Rc-httpd Project Rc-httpd | 3/4/2022 | 17/6/2026 | The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used. | |
| Modificada | Alta (7.5) | 1.3% | — | Unix4lyfe Darkhttpd | 1/4/2022 | 17/6/2026 | A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (5.9) | 8.9% | — | LighttpdDebian Linux | 6/1/2022 | 17/6/2026 | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded… | |
| Modificada | Crítica (9.8) | 8.7% | — | GNU LibmicrohttpdRedhat Enterprise LinuxFedoraproject Fedora | 25/3/2021 | 17/6/2026 | A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as… | |
| Modificada | Media (6.1) | 0.76% | — | Nanohttpd | 23/2/2021 | 17/6/2026 | An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that extends this class without implementing its own GET handler is vulnerable to reflected XSS, because the GeneralHandler… | |
| Modificada | Alta (7.5) | 1.4% | — | Sthttpd Project Sthttpd | 7/2/2021 | 17/6/2026 | An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this… | |
| Modificada | Media (5.4) | 0.33% | — | Redhat Jboss Core Services Httpd | 7/1/2021 | 17/6/2026 | A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The validation of the certificate whether CN and hostname are matching stopped working and allow connecting to the back-end work. The highest threat from this vulnerability is… | |
| Modificada | Crítica (9.8) | 1.3% | — | Acme Thttpd | 27/12/2019 | 16/6/2026 | thttpd 2007 has buffer underflow. | |
| Modificada | Media (5.5) | 0.39% | — | Acme Thttpd | 25/11/2019 | 16/6/2026 | thttpd has a local DoS vulnerability via specially-crafted .htpasswd files | |
| Modificada | Alta (7.5) | 20% | — | Nazgul Nostromo Nhttpd | 14/10/2019 | 17/6/2026 | A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Nazgul Nostromo Nhttpd | 14/10/2019 | 17/6/2026 | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request. | |
| Modificada | Alta (7) | 0.23% | — | Groonga-httpd | 2/5/2019 | 17/6/2026 | The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to… | |
| Modificada | Crítica (9.8) | 74% | — | Lighttpd | 10/4/2019 | 17/6/2026 | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer… | |
| Modificada | Alta (7.5) | 14% | — | LighttpdOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+1 | 7/11/2018 | 17/6/2026 | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does… |