Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)71%—Acme Mini-httpd29/10/201817/6/2026
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
ModificadaCrítica (9.8)40%—Xiongmaitech Uc-httpd8/6/201817/6/2026
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.
ModificadaCrítica (9.8)2.7%—Acme Mini HttpdAcme Thttpd6/2/201817/6/2026
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
ModificadaAlta (7.8)0.38%—Keycloak-httpd-client-install Project Keycloak-httpd-client-install20/1/201817/6/2026
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
ModificadaMedia (5.5)0.39%—Keycloak-httpd-client-install Project Keycloak-httpd-client-install20/1/201817/6/2026
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
ModificadaAlta (7.8)1.5%—Sthttpd Project Sthttpd29/6/201717/6/2026
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.
ModificadaCrítica (9.8)29%—Xiongmaitech Uc-httpd7/4/201717/6/2026
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
ModificadaAlta (7.5)9.9%—LighttpdHP Virtual Customer Access SystemOracle Solaris9/6/201517/6/2026
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character.
ModificadaMedia (5)1.6%—Acme Mini Httpd10/2/201517/6/2026
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
ModificadaMedia (4.3)1.5%—Ultrapop I-httpd12/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP header, a different vulnerability than CVE-2014-7261.
ModificadaMedia (4.3)1.8%—Ultrapop I-httpd12/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string.
ModificadaMedia (4.3)1.1%—Ultrapop I-httpd12/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than CVE-2014-7263.
ModificadaAlta (7.5)2.1%—Ultrapop I-httpd12/12/201417/6/2026
The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives.
ModificadaMedia (5)1.7%—Eterna BozohttpdNetbsd24/7/201417/6/2026
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.
ModificadaAlta (7.8)11%—Acme Micro HttpdDlink Dsl2740uDlink Dsl2750uNetgear Mr-adsl-dg834+124/7/201417/6/2026
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.
ModificadaMedia (5)30%—LighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+214/3/201417/6/2026
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
ModificadaCrítica (9.8)63%—LighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+114/3/201417/6/2026
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
ModificadaMedia (5.1)3.3%—GNU Libmicrohttpd13/12/201317/6/2026
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.
ModificadaMedia (6.4)1.8%—GNU Libmicrohttpd13/12/201317/6/2026
The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read.
ModificadaBaja (2.1)0.52%—Open Source Development Team SthttpdFedoraproject FedoraGentoo LinuxOpensuse+113/12/201316/6/2026
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
ModificadaMedia (5)5.4%—LighttpdDebian LinuxOpensuse20/11/201316/6/2026
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.
ModificadaAlta (7.6)11%—LighttpdDebian LinuxOpensuse20/11/201316/6/2026
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user…
ModificadaAlta (7.5)2.6%—LighttpdDebian LinuxOpensuse8/11/201316/6/2026
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
ModificadaAlta (10)64%—Vector Ultra Mini Httpd31/7/201316/6/2026
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request.
ModificadaBaja (1.9)0.35%—Lighttpd21/3/201316/6/2026
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack…