Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1211 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.1%—Lightbend Akka Http30/8/201817/6/2026
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
ModificadaMedia (6.1)4.0%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
ModificadaMedia (5.3)39%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
ModificadaMedia (6.1)20%💥 ExploitApache Http Server14/8/201817/6/2026
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed…
ModificadaMedia (6.5)8.1%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+126/7/201817/6/2026
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource.
ModificadaAlta (7.5)56%💥 ExploitApache Http ServerNetapp Cloud Backup18/7/201817/6/2026
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).
ModificadaMedia (4.7)0.83%—Atlassian Http Library18/7/201817/6/2026
The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml.
AnalizadaMedia (6.5)1.2%—Aio-libs Aiohttp Session26/6/201817/6/2026
aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can result in Session Hijacking. This attack appear to be exploitable via Any method that allows setting…
ModificadaAlta (7.5)17%—Apache Http ServerRedhat Jboss Core ServicesCanonical Ubuntu LinuxNetapp Cloud Backup+118/6/201817/6/2026
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
ModificadaCrítica (9.8)40%💥 ExploitXiongmaitech Uc-httpd8/6/201817/6/2026
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
ModificadaCrítica (9.1)2.0%—Https-proxy-agent Project Https-proxy-agent7/6/201817/6/2026
https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON).
ModificadaMedia (5.4)0.64%—Simplehttpserver Project Simplehttpserver7/6/201817/6/2026
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModificadaMedia (6.5)1.5%—Angular-http-server Project Angular-http-server7/6/201817/6/2026
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
ModificadaAlta (7.5)2.0%—Fast-http-cli Project Fast-http-cli7/6/201817/6/2026
fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Http Static Simple Project Http Static Simple7/6/201817/6/2026
http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Tiny-http Project Tiny-http7/6/201817/6/2026
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)2.0%—Iter-http Project Iter-http7/6/201817/6/2026
iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (7.5)1.2%—Http-proxy.js Project Http-proxy.js7/6/201817/6/2026
http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.7%—Http-proxy Project Http-proxy4/6/201817/6/2026
Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.
ModificadaAlta (7.5)0.86%—Joyent Http-signature4/6/201817/6/2026
Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the…
ModificadaAlta (8.1)1.7%—Httpsync Project Httpsync1/6/201817/6/2026
httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between…
ModificadaMedia (4.7)1.1%—SAP Netweaver Java WEB Container AND Http Service EngineSAP J2ee Engine Server Core9/5/201817/6/2026
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
ModificadaAlta (7.5)11%—Nghttp2Nodejs Node.jsDebian Linux8/5/201817/6/2026
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
ModificadaMedia (5.9)2.0%—Oracle Http Server19/4/201817/6/2026
Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OSSL Module). Supported versions that are affected are 12.1.3 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks…
ModificadaCrítica (9.8)16%—Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+926/3/201817/6/2026
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an…