Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 89% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+21 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers. | |
| Analizada | Alta (7.5) | 56% | — | Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxOpensuse Leap+9 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for… | |
| Modificada | Media (5.3) | 7.0% | — | Apache Http Server | 7/8/2020 | 17/6/2026 | IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof their IP address for logging and PHP scripts. Note this issue was fixed in Apache HTTP Server 2.4.24 but was retrospectively allocated a low… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Http ServerNetapp Clustered Data OntapCanonical Ubuntu LinuxDebian Linux+9 | 7/8/2020 | 17/6/2026 | Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE | |
| Modificada | Alta (7.5) | 1.8% | — | Fast-http Project Fast-http | 25/7/2020 | 17/6/2026 | This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js. | |
| Modificada | Alta (7.5) | 31% | — | Rejetto Http File Server | 8/6/2020 | 17/6/2026 | rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers. | |
| Modificada | Alta (7.5) | 5.3% | — | Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+6 | 3/6/2020 | 17/6/2026 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at… | |
| Modificada | Crítica (9.8) | 0.75% | — | Kaoni Ezhttptrans | 28/5/2020 | 17/6/2026 | Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by rebooting the victim’s PC. | |
| Modificada | Alta (7.4) | 0.91% | — | Em-http-request Project Em-http-requestFedoraproject Fedora | 25/5/2020 | 17/6/2026 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. | |
| Modificada | Crítica (9.8) | 0.75% | — | Kaoni Ezhttptrans | 22/5/2020 | 17/6/2026 | Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download and execute arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution. | |
| Modificada | Media (6.8) | 2.4% | — | Httplib2 Project Httplib2Fedoraproject FedoraDebian Linux | 20/5/2020 | 17/6/2026 | In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper… | |
| Modificada | Alta (7.5) | 1.8% | — | Http-client Project Http-client | 29/4/2020 | 17/6/2026 | Actions Http-Client (NPM @actions/http-client) before version 1.0.8 can disclose Authorization headers to incorrect domain in certain redirect scenarios. The conditions in which this happens are if consumers of the http-client: 1. make an http request with an authorization header 2. that request leads to a redirect… | |
| Modificada | Alta (7.5) | 53% | 💥 PoC | OpensslDebian LinuxFreebsdFedoraproject Fedora+22 | 21/4/2020 | 17/6/2026 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from… | |
| Modificada | Media (6.5) | 1.2% | — | Oracle Http Server | 15/4/2020 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this… | |
| Modificada | Alta (7.5) | 1.7% | — | Yhirose Cpp-httplib | 12/4/2020 | 17/6/2026 | cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts. | |
| Modificada | Media (6.1) | 57% | — | Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+10 | 2/4/2020 | 17/6/2026 | In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL. | |
| Modificada | Media (5.3) | 52% | — | Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+7 | 1/4/2020 | 17/6/2026 | In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. | |
| Modificada | Alta (7.5) | 7.0% | — | Typelevel Http4s | 25/3/2020 | 17/6/2026 | http4s before versions 0.18.26, 0.20.20, and 0.21.2 has a local file inclusion vulnerability. This vulnerability applies to all users of org.http4s.server.staticcontent.FileService, org.http4s.server.staticcontent.ResourceService and org.http4s.server.staticcontent.WebjarService. URI normalization is applied… | |
| Modificada | Media (6.5) | 1.3% | — | Wso2 Transport-http | 19/2/2020 | 17/6/2026 | Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled. | |
| Modificada | Baja (3.3) | 0.89% | — | Nghttp2Fedoraproject Fedora | 6/2/2020 | 17/6/2026 | nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion). | |
| Modificada | Media (5.3) | 1.5% | — | Oracle Http Server | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Http Server | 15/1/2020 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.… | |
| Modificada | Alta (7.5) | 0.83% | — | Http Authentication Library Project Http Authentication Library | 30/12/2019 | 17/6/2026 | The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used. | |
| Modificada | Crítica (9.8) | 1.3% | — | Acme Thttpd | 27/12/2019 | 16/6/2026 | thttpd 2007 has buffer underflow. | |
| Modificada | Crítica (9.8) | 8.4% | 💥 Exploit | Static Http Server Project Static Http Server | 27/12/2019 | 16/6/2026 | Static HTTP Server 1.0 has a Local Overflow |