Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.27% | — | Yhirose Cpp-httplib | 5/12/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can supply X-Forwarded-For or X-Real-IP headers which get accepted… | |
| Analizada | Crítica (9.8) | 0.33% | — | Yhirose Cpp-httplib | 5/12/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can inject headers named REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, LOCAL_PORT… | |
| Analizada | Alta (7.5) | 0.55% | — | Yhirose Cpp-httplib | 10/7/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.23.0, incoming requests using Transfer-Encoding: chunked in the header can allocate memory arbitrarily in the server, potentially leading to its exhaustion. This vulnerability is fixed in 0.23.0. NOTE: This vulnerability is… | |
| Analizada | Media (6.3) | 0.49% | — | Yhirose Cpp-httplib | 10/7/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.20.1, cpp-httplib does not have a limit for a unique line, permitting an attacker to explore this to allocate memory arbitrarily. This vulnerability is fixed in 0.20.1. NOTE: This vulnerability is related to CVE-2025-53629. | |
| Analizada | Alta (7.5) | 0.49% | — | Yhirose Cpp-httplib | 26/6/2025 | 17/6/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In version 0.21.0, when many http headers fields are passed in, the library does not limit the number of headers, and the memory associated with the headers will not be released when the connection is disconnected. This leads to… | |
| Analizada | Alta (7.5) | 0.66% | — | Cpp-httplib Project Cpp-httplib | 6/5/2025 | 17/6/2026 | cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked request without… | |
| Analizada | Media (6.9) | 0.41% | — | Yhirose Cpp-httplib | 4/2/2025 | 17/6/2026 | cpp-httplib version v0.17.3 through v0.18.3 fails to filter CRLF characters ("\r\n") when those are prefixed with a null byte. This enables attackers to exploit CRLF injection that could further lead to HTTP Response Splitting, XSS, and more. | |
| Analizada | Alta (7.5) | 0.60% | — | Gdraheim Zziplib | 27/6/2024 | 17/6/2026 | A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c. | |
| Analizada | Media (4.3) | 0.50% | — | Zziplib Project Zziplib | 27/6/2024 | 17/6/2026 | Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c. | |
| Aplazada | Alta (8.1) | 0.51% | — | AsdcplibAI | 31/5/2024 | 17/6/2026 | asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so. | |
| Modificada | Media (5.5) | 0.34% | — | Gdraheim Zziplib | 22/8/2023 | 17/6/2026 | An issue was discovered in function zzip_disk_entry_to_file_header in mmapped.c in zziplib 0.13.69, which will lead to a denial-of-service. | |
| Modificada | Alta (8.8) | 1.1% | — | Cpp-httplib Project Cpp-httplib | 30/5/2023 | 17/6/2026 | Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the content-type header in the HTTP .Patch, .Post, .Put and .Delete requests. This can lead to logical errors and other misbehaviors. **Note:** This issue is present due to an incomplete… | |
| Modificada | Media (6.5) | 0.69% | — | Diplib | 4/11/2022 | 17/6/2026 | diplib v3.0.0 is vulnerable to Double Free. | |
| Modificada | Media (5.3) | 1.1% | — | Sharpziplib Project Sharpziplib | 26/1/2022 | 17/6/2026 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced that `destDir` ends with slash. If the `destDir` is not slash terminated like `/home/user/dir` it is… | |
| Modificada | Media (5.3) | 0.90% | — | Sharpziplib Project Sharpziplib | 26/1/2022 | 17/6/2026 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced that `_baseDirectory` ends with slash. If the _baseDirectory is not slash terminated like… | |
| Modificada | Crítica (9.8) | 1.9% | — | Sharpziplib Project Sharpziplib | 26/1/2022 | 17/6/2026 | SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in version 1.3.3. | |
| Modificada | Alta (7.5) | 3.7% | — | Gmplib GMPDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 15/11/2021 | 17/6/2026 | GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms. | |
| Modificada | Alta (8.8) | 2.8% | — | Plib Project PlibDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 24/8/2021 | 17/6/2026 | In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. | |
| Modificada | Baja (3.3) | 0.74% | — | Gdraheim ZziplibDebian LinuxFedoraproject Fedora | 18/6/2021 | 17/6/2026 | Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file". | |
| Modificada | Alta (7.5) | 3.6% | — | Httplib2 Project Httplib2 | 8/2/2021 | 17/6/2026 | httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed… | |
| Modificada | Media (6.8) | 2.4% | — | Httplib2 Project Httplib2Fedoraproject FedoraDebian Linux | 20/5/2020 | 17/6/2026 | In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper… | |
| Modificada | Alta (7.5) | 1.7% | — | Yhirose Cpp-httplib | 12/4/2020 | 17/6/2026 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts. | |
| Modificada | Media (5.5) | 1.5% | — | Gdraheim Zziplib | 1/10/2018 | 17/6/2026 | Directory traversal vulnerability in ZZIPlib 0.13.69 allows attackers to overwrite arbitrary files via a .. (dot dot) in a zip file, because of the function unzzip_cat in the bins/unzzipcat-mem.c file. | |
| Modificada | Media (6.5) | 1.9% | — | Gdraheim Zziplib | 5/9/2018 | 17/6/2026 | An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack. | |
| Modificada | Media (5.5) | 9.9% | — | Sharpziplib Project Sharpziplib | 25/7/2018 | 17/6/2026 | SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. |