Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1211 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Gohttp Project Gohttp20/5/201917/6/2026
In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header.
ModificadaCrítica (9.8)1.7%—Gohttp Project Gohttp17/5/201917/6/2026
GoHTTP through 2017-07-25 has a sendHeader use-after-free.
ModificadaAlta (7.5)1.3%—Gohttp Project Gohttp17/5/201917/6/2026
GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via a long URL.
ModificadaCrítica (9.8)1.6%—Gohttp Project Gohttp17/5/201917/6/2026
GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension.
ModificadaAlta (7)0.23%—Groonga-httpd2/5/201917/6/2026
The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let local users obtain root access because of unsafe interaction with logrotate. For example, an attacker can exploit a race condition to insert a symlink from /var/log/groonga/httpd to…
ModificadaMedia (5.9)2.5%—Squareup Okhttp18/4/201917/6/2026
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application. NOTE: This id is disputed because some parties don't consider this is a vulnerability. Their rationale can be found in…
ModificadaCrítica (9.8)74%—Lighttpd10/4/201917/6/2026
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious HTTP GET request, as demonstrated by mishandling of /%2F? in burl_normalize_2F_to_slash_fix in burl.c. NOTE: The developer…
AnalizadaAlta (7.8)65%⚠ Explotación activa💥 ExploitApache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+238/4/201917/6/2026
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating…
ModificadaAlta (7.5)17%💥 PoCApache Http ServerDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+108/4/201917/6/2026
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
ModificadaAlta (7.5)11%—Apache Http ServerFedoraproject Fedora8/4/201917/6/2026
In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verification with TLSv1.3 allowed a client to bypass configured access control restrictions.
ModificadaAlta (7.5)2.8%—Http-live-simulator Project Http-live-simulator3/4/201917/6/2026
Path traversal vulnerability in http-live-simulator npm package version 1.0.5 allows arbitrary path to be accessed on the file system by a remote attacker.
ModificadaAlta (7.5)4.3%—Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+36/2/201917/6/2026
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond…
ModificadaCrítica (9.8)13%—Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+126/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent…
ModificadaAlta (7.5)5.4%💥 PoCHaxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+66/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a…
ModificadaAlta (7.5)1.7%—Http-live-simulator Project Http-live-simulator1/2/201917/6/2026
Path traversal vulnerability in http-live-simulator <1.0.7 causes unauthorized access to arbitrary files on disk by appending extra slashes after the URL.
ModificadaAlta (7.5)59%—Apache Http ServerOracle Enterprise Manager OPS CenterOracle Hospitality Guest AccessOracle Instantis Enterprisetrack+130/1/201917/6/2026
A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an…
ModificadaAlta (7.5)20%—Apache Http ServerDebian LinuxNetapp Santricity Cloud ConnectorNetapp Storage Automation Store+230/1/201917/6/2026
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.
ModificadaMedia (5.3)20%—Apache Http ServerNetapp Santricity Cloud ConnectorNetapp Storage Automation StoreFedoraproject Fedora+830/1/201917/6/2026
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
ModificadaAlta (7.8)0.45%—Oracle Http Server16/1/201917/6/2026
Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: Web Listener). The supported version that is affected is 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP…
ModificadaMedia (6.5)0.97%—Aio-libs Aiohttp Session20/12/201817/6/2026
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
ModificadaMedia (5.3)1.3%—Simplehttpserver Project Simplehttpserver4/12/201817/6/2026
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
ModificadaAlta (7.5)14%💥 PoCLighttpdOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+17/11/201817/6/2026
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does…
ModificadaMedia (6.5)71%💥 ExploitAcme Mini-httpd29/10/201817/6/2026
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
ModificadaMedia (5.9)51%—Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise LinuxOracle Enterprise Manager OPS Center+525/9/201817/6/2026
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
ModificadaAlta (7.5)2.0%—Simplehttpserver Project Simplehttpserver31/8/201817/6/2026
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
Orbitaley — Vulnerabilidades