Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1211 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.4%—Http-swagger Project Http-swagger18/4/202217/6/2026
http-swagger is an open source wrapper to automatically generate RESTful API documentation with Swagger 2.0. In versions of http-swagger prior to 1.2.6 an attacker may perform a denial of service attack consisting of memory exhaustion on the host system. The cause of the memory exhaustion is down to improper handling…
ModificadaAlta (7.5)1.5%—Rc-httpd Project Rc-httpd3/4/202217/6/2026
The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used.
ModificadaAlta (7.5)1.3%—Unix4lyfe Darkhttpd1/4/202217/6/2026
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.
ModificadaAlta (7.5)2.5%—Fasthttp Project Fasthttp17/3/202217/6/2026
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue impacts Windows users only.
ModificadaMedia (5.3)1.3%—Httpie15/3/202217/6/2026
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository httpie/httpie prior to 3.1.0.
AnalizadaCrítica (9.8)50%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Http Server+114/3/202217/6/2026
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
ModificadaCrítica (9.1)42%—Apache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
ModificadaCrítica (9.8)28%💥 PoCApache Http ServerFedoraproject FedoraDebian LinuxOracle Enterprise Manager OPS Center+414/3/202217/6/2026
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
ModificadaAlta (7.5)69%—Apache Http ServerDebian LinuxFedoraproject FedoraOracle Http Server+314/3/202217/6/2026
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
ModificadaAlta (7.5)1.3%—Apple Swiftnio Http/210/3/202217/6/2026
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS or HTTP/2 PUSH_PROMISE frame where the frame contains padding information without any other data.…
ModificadaMedia (6.5)1.7%—HttpieFedoraproject Fedora7/3/202217/6/2026
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This…
ModificadaAlta (7.5)3.5%—TwistedDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+13/3/202217/6/2026
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc…
ModificadaMedia (6.1)0.62%—Element-it Http Commander3/3/20229/7/2026
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
ModificadaCrítica (9.8)4.8%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
ModificadaAlta (7.5)4.7%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.
ModificadaMedia (6.5)3.3%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+218/2/202217/6/2026
In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
ModificadaCrítica (9.8)34%💥 PoCLibexpat Project LibexpatDebian LinuxOracle Http ServerOracle ZFS Storage Appliance KIT+116/2/202217/6/2026
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
ModificadaCrítica (9.8)5.0%💥 PoCLibexpat Project LibexpatDebian LinuxFedoraproject FedoraOracle Http Server+216/2/202217/6/2026
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
ModificadaAlta (7.5)1.1%—Apple Swiftnio Http/29/2/202217/6/2026
A program using swift-nio-http2 is vulnerable to a denial of service attack caused by a network peer sending ALTSVC or ORIGIN frames. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error after frame parsing but before frame handling. ORIGIN and ALTSVC…
ModificadaAlta (7.5)1.1%—Apple Swiftnio Http/29/2/202217/6/2026
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HPACK-encoded header block. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. There are a number of implementation errors in the parsing of HPACK-encoded header blocks…
ModificadaAlta (7.5)1.4%—Apple Swiftnio Http/29/2/202217/6/2026
A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a specially crafted HTTP/2 frame. This attack affects all swift-nio-http2 versions from 1.0.0 to 1.19.1. This vulnerability is caused by a logical error when parsing a HTTP/2 HEADERS frame where the frame…
ModificadaAlta (7.5)8.3%—PythonNetapp Active IQ Unified ManagerNetapp HCINetapp Management Services FOR Element Software+69/2/202217/6/2026
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a…
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitPolkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2628/1/202215/8/2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends…
ModificadaMedia (5.5)0.26%—Oracle Http ServerOracle ZFS Storage Appliance KITOracle Solaris19/1/202217/6/2026
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this…
ModificadaMedia (5.3)2.8%—Oracle GraalvmOracle Http ServerOracle JDKOracle JRE+1519/1/202217/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker…
Orbitaley — Vulnerabilidades