Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | — | Http Server Project Http Server | 18/12/2019 | 17/6/2026 | A Path traversal exists in http_server which allows an attacker to read arbitrary system files. | |
| Modificada | Media (5.5) | 0.39% | — | Acme Thttpd | 25/11/2019 | 16/6/2026 | thttpd has a local DoS vulnerability via specially-crafted .htpasswd files | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | Nazgul Nostromo Nhttpd | 14/10/2019 | 17/6/2026 | A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Nazgul Nostromo Nhttpd | 14/10/2019 | 17/6/2026 | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request. | |
| Modificada | Alta (7.2) | 53% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+4 | 26/9/2019 | 17/6/2026 | In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability could only be triggered by a trusted proxy and not by… | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Apache Http ServerOpensuse LeapDebian LinuxRedhat Software Collection+6 | 26/9/2019 | 17/6/2026 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but… | |
| Modificada | Crítica (9.1) | 17% | — | Apache Http ServerOracle Communications Element ManagerOracle Enterprise Manager OPS CenterOracle Http Server+2 | 26/9/2019 | 17/6/2026 | In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memory after being freed, during connection shutdown. | |
| Modificada | Media (6.1) | 74% | 💥 Exploit | Apache Http Server | 25/9/2019 | 17/6/2026 | In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL. | |
| Modificada | Crítica (9.8) | 18% | — | Haxx CurlFedoraproject FedoraOpensuse LeapNetapp Cloud Backup+13 | 16/9/2019 | 17/6/2026 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. | |
| Modificada | Crítica (9.8) | 6.8% | — | PHP Ext-http | 6/9/2019 | 17/6/2026 | A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and earlier as well as 2.6.0beta2 (PHP 5) and earlier allows attackers to crash PHP and possibly execute arbitrary code via crafted HTTP requests. | |
| Modificada | Media (5.3) | 1.6% | — | Statichttpserver Project Statichttpserver | 3/9/2019 | 17/6/2026 | A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders. | |
| Modificada | Alta (8.8) | 2.0% | — | Httpie | 23/8/2019 | 17/6/2026 | All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing to a server in his or hers control. | |
| Modificada | Alta (7.5) | 15% | — | Apache Http ServerDebian Linux | 15/8/2019 | 17/6/2026 | HTTP/2 (2.4.20 through 2.4.39) very early pushes, for example configured with "H2PushResource", could lead to an overwrite of memory in the pushing request's pool, leading to crashes. The memory copied is that of the configured push link header values, not data supplied by the client. | |
| Modificada | Alta (7.5) | 28% | — | Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+19 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The… | |
| Modificada | Media (5.4) | 0.71% | — | Http-file-server Project Http-file-server | 30/7/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. | |
| Modificada | Media (5.4) | 0.71% | — | Min-http-server Project Min-http-server | 30/7/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser. | |
| Modificada | Media (5.9) | 1.4% | — | Oracle Http Server | 23/7/2019 | 17/6/2026 | Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OHS Config MBeans). Supported versions that are affected are 12.1.3.0.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.… | |
| Modificada | Media (5.9) | 0.57% | — | Http Request Project Http Request | 23/7/2019 | 17/6/2026 | OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing. | |
| Modificada | Media (5.3) | 1.5% | — | Http-file-server Project Http-file-server | 15/7/2019 | 17/6/2026 | A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders. | |
| Modificada | Alta (7.8) | 0.69% | — | Haxx CurlOracle Enterprise Manager OPS CenterOracle Http ServerOracle Mysql Server+5 | 2/7/2019 | 17/6/2026 | A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants. | |
| Modificada | Alta (7.5) | 7.1% | — | Libexpat Project LibexpatCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+5 | 24/6/2019 | 17/6/2026 | In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks). | |
| Modificada | Media (4.2) | 8.6% | — | Apache Http ServerCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+7 | 11/6/2019 | 17/6/2026 | A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled… | |
| Modificada | Media (5.3) | 20% | — | Apache Http ServerCanonical Ubuntu LinuxDebian Linux | 11/6/2019 | 17/6/2026 | A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly. | |
| Modificada | Media (5.3) | 18% | — | Apache Http ServerOpensuse LeapDebian LinuxFedoraproject Fedora+1 | 11/6/2019 | 17/6/2026 | A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the servers processing will implicitly… |