Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 71% | — | Acme Mini-httpd | 29/10/2018 | 17/6/2026 | ACME mini_httpd before 1.30 lets remote users read arbitrary files. | |
| Modificada | Crítica (9.8) | 40% | — | Xiongmaitech Uc-httpd | 8/6/2018 | 17/6/2026 | Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725. | |
| Modificada | Crítica (9.8) | 2.7% | — | Acme Mini HttpdAcme Thttpd | 6/2/2018 | 17/6/2026 | The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. | |
| Modificada | Alta (7.8) | 0.38% | — | Keycloak-httpd-client-install Project Keycloak-httpd-client-install | 20/1/2018 | 17/6/2026 | keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users. | |
| Modificada | Media (5.5) | 0.39% | — | Keycloak-httpd-client-install Project Keycloak-httpd-client-install | 20/1/2018 | 17/6/2026 | keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link. | |
| Modificada | Alta (7.8) | 1.5% | — | Sthttpd Project Sthttpd | 29/6/2017 | 17/6/2026 | Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename. | |
| Modificada | Crítica (9.8) | 29% | — | Xiongmaitech Uc-httpd | 7/4/2017 | 17/6/2026 | XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request. | |
| Modificada | Alta (7.5) | 9.9% | — | LighttpdHP Virtual Customer Access SystemOracle Solaris | 9/6/2015 | 17/6/2026 | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character. | |
| Modificada | Media (5) | 1.6% | — | Acme Mini Httpd | 10/2/2015 | 17/6/2026 | mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read. | |
| Modificada | Media (4.3) | 1.5% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP header, a different vulnerability than CVE-2014-7261. | |
| Modificada | Media (4.3) | 1.8% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string. | |
| Modificada | Media (4.3) | 1.1% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than CVE-2014-7263. | |
| Modificada | Alta (7.5) | 2.1% | — | Ultrapop I-httpd | 12/12/2014 | 17/6/2026 | The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives. | |
| Modificada | Media (5) | 1.7% | — | Eterna BozohttpdNetbsd | 24/7/2014 | 17/6/2026 | bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path. | |
| Modificada | Alta (7.8) | 11% | — | Acme Micro HttpdDlink Dsl2740uDlink Dsl2750uNetgear Mr-adsl-dg834+1 | 24/7/2014 | 17/6/2026 | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request. | |
| Modificada | Media (5) | 30% | — | LighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+2 | 14/3/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname. | |
| Modificada | Crítica (9.8) | 63% | — | LighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+1 | 14/3/2014 | 17/6/2026 | SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname. | |
| Modificada | Media (5.1) | 3.3% | — | GNU Libmicrohttpd | 13/12/2013 | 17/6/2026 | Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header. | |
| Modificada | Media (6.4) | 1.8% | — | GNU Libmicrohttpd | 13/12/2013 | 17/6/2026 | The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read. | |
| Modificada | Baja (2.1) | 0.52% | — | Open Source Development Team SthttpdFedoraproject FedoraGentoo LinuxOpensuse+1 | 13/12/2013 | 16/6/2026 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (5) | 5.4% | — | LighttpdDebian LinuxOpensuse | 20/11/2013 | 16/6/2026 | Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures. | |
| Modificada | Alta (7.6) | 11% | — | LighttpdDebian LinuxOpensuse | 20/11/2013 | 16/6/2026 | lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user… | |
| Modificada | Alta (7.5) | 2.6% | — | LighttpdDebian LinuxOpensuse | 8/11/2013 | 16/6/2026 | lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network. | |
| Modificada | Alta (10) | 64% | — | Vector Ultra Mini Httpd | 31/7/2013 | 16/6/2026 | Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request. | |
| Modificada | Baja (1.9) | 0.35% | — | Lighttpd | 21/3/2013 | 16/6/2026 | The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack… |