Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1211 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.74%—Element-it Http Commander13/1/202217/6/2026
A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames.
ModificadaMedia (5.9)8.9%—LighttpdDebian Linux6/1/202217/6/2026
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded…
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaMedia (5.5)1.5%—WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT30/12/202117/6/2026
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
ModificadaAlta (7.5)3.2%—WiresharkFedoraproject FedoraOracle Http ServerOracle ZFS Storage Appliance KIT30/12/202117/6/2026
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
ModificadaAlta (7.5)3.8%—WiresharkFedoraproject FedoraDebian LinuxOracle Http Server+130/12/202117/6/2026
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
AnalizadaCrítica (9.8)97%💥 ExploitApache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+1020/12/202117/6/2026
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
ModificadaAlta (8.2)82%—Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+820/12/202117/6/2026
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue…
ModificadaCrítica (9.8)1.7%💥 PoCHttp-server-node Project Http-server-node17/12/202117/6/2026
All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
ModificadaAlta (7.1)2.7%—LxmlFedoraproject FedoraDebian LinuxNetapp Solidfire+713/12/202117/6/2026
lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade…
ModificadaAlta (7.5)3.2%💥 PoCOwasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+27/12/202117/6/2026
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for…
ModificadaMedia (6.5)3.2%—LlhttpOracle GraalvmDebian Linux15/11/202117/6/2026
The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS) in llhttp < v2.1.4 and < v6.0.6.
ModificadaMedia (6.5)2.5%—LlhttpOracle GraalvmDebian Linux3/11/202117/6/2026
The parse function in llhttp < 2.1.4 and < 6.0.6. ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions.
ModificadaAlta (7.5)36%💥 ExploitAkka Http Server2/11/202117/6/2026
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
ModificadaAlta (7.5)0.98%—C-http Project C-http2/11/202117/6/2026
Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function.
ModificadaMedia (5.3)11%—ISC BindDebian LinuxFedoraproject FedoraNetapp H300s Firmware+1127/10/202117/6/2026
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause…
ModificadaMedia (5.9)1.2%—Oracle Http Server20/10/202117/6/2026
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this…
ModificadaBaja (3.7)0.83%—Oracle Http Server20/10/202117/6/2026
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackOracle JD Edwards Enterpriseone Tools+27/10/202117/6/2026
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackNetapp Cloud Backup5/10/202117/6/2026
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all…
ModificadaAlta (7.5)25%—Apache Http ServerFedoraproject FedoraOracle Instantis EnterprisetrackNetapp Cloud Backup5/10/202117/6/2026
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
ModificadaAlta (7)2.5%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+826/9/202114/7/2026
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of…
ModificadaMedia (4.7)1.2%—Typelevel Http4s21/9/202117/6/2026
http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or request-splitting attacks when untrusted user input is used to create any of the following fields: Header names (`Header.name`å), Header values (`Header.value`), Status reason phrases…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Orbitaley — Vulnerabilidades