Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.74% | — | Element-it Http Commander | 13/1/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames. | |
| Modificada | Media (5.9) | 8.9% | — | LighttpdDebian Linux | 6/1/2022 | 17/6/2026 | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded… | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Media (5.5) | 1.5% | — | WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT | 30/12/2021 | 17/6/2026 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file | |
| Modificada | Alta (7.5) | 3.2% | — | WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT | 30/12/2021 | 17/6/2026 | Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Modificada | Alta (7.5) | 3.8% | — | WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+1 | 30/12/2021 | 17/6/2026 | Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. | |
| Modificada | Alta (8.2) | 82% | — | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+8 | 20/12/2021 | 17/6/2026 | A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue… | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Http-server-node Project Http-server-node | 17/12/2021 | 17/6/2026 | All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. | |
| Modificada | Alta (7.1) | 2.7% | — | LxmlFedoraproject FedoraDebian LinuxNetapp Solidfire+7 | 13/12/2021 | 17/6/2026 | lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade… | |
| Modificada | Alta (7.5) | 3.2% | 💥 PoC | Owasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+2 | 7/12/2021 | 17/6/2026 | ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for… | |
| Modificada | Media (6.5) | 3.2% | — | LlhttpOracle GraalvmDebian Linux | 15/11/2021 | 17/6/2026 | The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6. | |
| Modificada | Media (6.5) | 2.5% | — | LlhttpOracle GraalvmDebian Linux | 3/11/2021 | 17/6/2026 | The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. | |
| Modificada | Alta (7.5) | 36% | 💥 Exploit | Akka Http Server | 2/11/2021 | 17/6/2026 | Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments. | |
| Modificada | Alta (7.5) | 0.98% | — | C-http Project C-http | 2/11/2021 | 17/6/2026 | Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function. | |
| Modificada | Media (5.3) | 11% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+11 | 27/10/2021 | 17/6/2026 | In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause… | |
| Modificada | Media (5.9) | 1.2% | — | Oracle Http Server | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this… | |
| Modificada | Baja (3.7) | 0.83% | — | Oracle Http Server | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackOracle JD Edwards Enterpriseone Tools+2 | 7/10/2021 | 17/6/2026 | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackNetapp Cloud Backup | 5/10/2021 | 17/6/2026 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all… | |
| Modificada | Alta (7.5) | 25% | — | Apache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackNetapp Cloud Backup | 5/10/2021 | 17/6/2026 | While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project. | |
| Modificada | Alta (7) | 2.5% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+8 | 26/9/2021 | 14/7/2026 | sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of… | |
| Modificada | Media (4.7) | 1.2% | — | Typelevel Http4s | 21/9/2021 | 17/6/2026 | http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values (`Header.value`), Status reason phrases… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |