Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Crítica (9.8) | 0.72% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Alta (8.1) | 0.78% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteOracle DatabaseOracle Http Server+2 | 11/7/2022 | 17/6/2026 | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability. | |
| Modificada | Media (6.5) | 2.3% | — | Http\ \Debian Linux | 27/6/2022 | 17/6/2026 | HTTP::Daemon is a simple http server class written in perl. Versions prior to 6.15 are subject to a vulnerability which could potentially be exploited to gain privileged access to APIs or poison intermediate caches. It is uncertain how large the risks are, most Perl based applications are served on top of Nginx or… | |
| Modificada | Media (5.5) | 0.72% | — | Aiohttp | 23/6/2022 | 17/6/2026 | AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: multiple third parties dispute this issue because there is no example of a context in which denial of service would occur, and many common contexts have exception handing in the calling application | |
| Modificada | Alta (7.5) | 57% | 💥 PoC | Lighttpd | 11/6/2022 | 17/6/2026 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers. | |
| Analizada | Crítica (9.8) | 3.5% | 💥 PoC | Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora | 9/6/2022 | 17/6/2026 | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. | |
| Analizada | Alta (7.5) | 5.3% | — | Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora | 9/6/2022 | 17/6/2026 | Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. | |
| Modificada | Alta (7.5) | 90% | — | Apache Http ServerNetapp Clustered Data OntapFedoraproject Fedora | 9/6/2022 | 17/6/2026 | If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | |
| Modificada | Alta (7.5) | 6.4% | — | Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap | 9/6/2022 | 17/6/2026 | In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. | |
| Modificada | Crítica (9.1) | 6.3% | — | Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap | 9/6/2022 | 17/6/2026 | Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may… | |
| Modificada | Media (5.3) | 5.0% | — | Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap | 9/6/2022 | 17/6/2026 | The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the… | |
| Modificada | Media (5.3) | 3.8% | — | Apache Http Server | 9/6/2022 | 17/6/2026 | Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module. | |
| Analizada | Alta (7.5) | 21% | 💥 PoC | Apache Http ServerFedoraproject FedoraNetapp Clustered Data Ontap | 9/6/2022 | 17/6/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions. | |
| Modificada | Alta (8.1) | 1.2% | — | Http File Server Project Http File Server | 9/6/2022 | 17/6/2026 | The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write. | |
| Modificada | Alta (7.5) | 0.99% | — | Jodd Http | 6/6/2022 | 17/6/2026 | Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload. | |
| Modificada | Alta (7.5) | 1.1% | — | Dell Bsafe Micro-edition-suiteOracle DatabaseOracle Http ServerOracle Security Service+1 | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. | |
| Modificada | Alta (7.5) | 0.69% | — | Dell Bsafe Micro-edition-suiteOracle Http ServerOracle Security ServiceOracle Weblogic Server Proxy Plug-in | 1/6/2022 | 17/6/2026 | Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain an Improper Certificate Validation vulnerability. | |
| Modificada | Media (5.5) | 0.30% | — | Nanohttpd | 1/5/2022 | 17/6/2026 | This affects all versions of package org.nanohttpd:nanohttpd. Whenever an HTTP Session is parsing the body of an HTTP request, the body of the request is written to a RandomAccessFile when the it is larger than 1024 bytes. This file is created with insecure permissions that allow its contents to be viewed by all users… | |
| Modificada | Crítica (9.8) | 2.3% | — | Smallsrv Small Http Server | 29/4/2022 | 17/6/2026 | Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. | |
| Modificada | Crítica (9.1) | 2.1% | — | Encode Httpx | 28/4/2022 | 9/7/2026 | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. |