Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1211 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.1% | — | Lightbend Akka Http | 30/8/2018 | 17/6/2026 | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Cybrotech Cybrohttpserver | 29/8/2018 | 17/6/2026 | Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. | |
| Modificada | Media (5.3) | 39% | 💥 Exploit | Cybrotech Cybrohttpserver | 29/8/2018 | 17/6/2026 | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | |
| Modificada | Media (6.1) | 20% | 💥 Exploit | Apache Http Server | 14/8/2018 | 17/6/2026 | Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed… | |
| Modificada | Media (6.5) | 8.1% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 26/7/2018 | 17/6/2026 | A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator could unintentionally allow any client to access a restricted HTTP resource. | |
| Modificada | Alta (7.5) | 56% | 💥 Exploit | Apache Http ServerNetapp Cloud Backup | 18/7/2018 | 17/6/2026 | By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33). | |
| Modificada | Media (4.7) | 0.83% | — | Atlassian Http Library | 18/7/2018 | 17/6/2026 | The atlassian-http library, as used in various Atlassian products, before version 2.0.2 allows remote attackers to spoof web content in the Mozilla Firefox Browser through uploaded files that have a content-type of application/mathml+xml. | |
| Analizada | Media (6.5) | 1.2% | — | Aio-libs Aiohttp Session | 26/6/2018 | 17/6/2026 | aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can result in Session Hijacking. This attack appear to be exploitable via Any method that allows setting… | |
| Modificada | Alta (7.5) | 17% | — | Apache Http ServerRedhat Jboss Core ServicesCanonical Ubuntu LinuxNetapp Cloud Backup+1 | 18/6/2018 | 17/6/2026 | By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33). | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Xiongmaitech Uc-httpd | 8/6/2018 | 17/6/2026 | Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. | |
| Modificada | Crítica (9.1) | 2.0% | — | Https-proxy-agent Project Https-proxy-agent | 7/6/2018 | 17/6/2026 | https-proxy-agent before 2.1.1 passes auth option to the Buffer constructor without proper sanitization, resulting in DoS and uninitialized memory leak in setups where an attacker could submit typed input to the 'auth' parameter (e.g. JSON). | |
| Modificada | Media (5.4) | 0.64% | — | Simplehttpserver Project Simplehttpserver | 7/6/2018 | 17/6/2026 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | |
| Modificada | Media (6.5) | 1.5% | — | Angular-http-server Project Angular-http-server | 7/6/2018 | 17/6/2026 | angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path. | |
| Modificada | Alta (7.5) | 2.0% | — | Fast-http-cli Project Fast-http-cli | 7/6/2018 | 17/6/2026 | fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Http Static Simple Project Http Static Simple | 7/6/2018 | 17/6/2026 | http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Tiny-http Project Tiny-http | 7/6/2018 | 17/6/2026 | tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Iter-http Project Iter-http | 7/6/2018 | 17/6/2026 | iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 1.2% | — | Http-proxy.js Project Http-proxy.js | 7/6/2018 | 17/6/2026 | http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.7% | — | Http-proxy Project Http-proxy | 4/6/2018 | 17/6/2026 | Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service. | |
| Modificada | Alta (7.5) | 0.86% | — | Joyent Http-signature | 4/6/2018 | 17/6/2026 | Http-signature is a "Reference implementation of Joyent's HTTP Signature Scheme". In versions <=0.9.11, http-signature signs only the header values, but not the header names. This makes http-signature vulnerable to header forgery. Thus, if an attacker can intercept a request, he can swap header names and change the… | |
| Modificada | Alta (8.1) | 1.7% | — | Httpsync Project Httpsync | 1/6/2018 | 17/6/2026 | httpsync is a port of libcurl to node.js. httpsync downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between… | |
| Modificada | Media (4.7) | 1.1% | — | SAP Netweaver Java WEB Container AND Http Service EngineSAP J2ee Engine Server Core | 9/5/2018 | 17/6/2026 | SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed. | |
| Modificada | Alta (7.5) | 11% | — | Nghttp2Nodejs Node.jsDebian Linux | 8/5/2018 | 17/6/2026 | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1. | |
| Modificada | Media (5.9) | 2.0% | — | Oracle Http Server | 19/4/2018 | 17/6/2026 | Vulnerability in the Oracle HTTP Server component of Oracle Fusion Middleware (subcomponent: OSSL Module). Supported versions that are affected are 12.1.3 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks… | |
| Modificada | Crítica (9.8) | 16% | — | Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+9 | 26/3/2018 | 17/6/2026 | In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an… |