Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
3872 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.48% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via concurrent Digest authentication requests when AuthDigestNcCheck is enabled or AuthDigestNonceLifetime is set to 0.… | |
| Analizada | Alta (8.1) | 0.41% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry… | |
| En análisis | Alta (7.5) | 0.32% | — | Apache Http ServerAI | 1/10/2026 | 1/10/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.48% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version… | |
| Analizada | Alta (7.5) | 0.88% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname… | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response.… | |
| Analizada | Crítica (9.8) | 0.52% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (5.3) | 0.53% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties of resources it cannot author via a GET request for the .DAV state directory This issue affects Apache HTTP Server:… | |
| Analizada | Crítica (9.8) | 0.60% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Crítica (9.8) | 0.56% | — | Apache Http Server | 1/10/2026 | 5/10/2026 | Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.50% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.61% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck… | |
| Analizada | Alta (7.5) | 0.39% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Alta (7.5) | 0.47% | — | Apache Http Server | 1/10/2026 | 2/10/2026 | NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68. | |
| Analizada | Media (4.3) | 0.42% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue | |
| Analizada | Baja (3.7) | 0.47% | — | Apache Http Server | 1/10/2026 | 6/10/2026 | Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server:… | |
| Aplazada | Media (5.1) | 0.49% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Improper Authentication vulnerability in Apache APISIX. On a route using openid-connect plugin with remote introspection against an authorization server that serves multiple issuers, a token that introspects as active for one issuer may get accepted on a route restricted to another. This issue affects Apache APISIX:… | |
| Aplazada | Media (6.3) | 0.42% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Use of Non-Canonical URL paths for authorization decisions vulnerability in Apache APISIX. In some configurations where a permissive route overlaps a protected one, a crafted encoded path can reach an upstream endpoint that the matched route's policies were never meant to cover. A request that should have been… | |
| Aplazada | Alta (8.2) | 0.32% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0… | |
| Aplazada | Baja (2.1) | 0.22% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then… | |
| Aplazada | Media (6.4) | 0.27% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Improper verification of cryptographic signature vulnerability in Apache APISIX. Any unauthenticated attacker could impersonate any user on every route protected by the saml-auth plugin under default configuration. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to… | |
| Aplazada | Alta (8.6) | 0.52% | — | Apache Camel QuarkusAI | 1/10/2026 | 1/10/2026 | Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0 on all platforms allows an attacker who supplies the XML document being transformed to read local files or issue requests to… | |
| Aplazada | Media (5.3) | 0.40% | — | Apache ApisixAI | 1/10/2026 | 1/10/2026 | Exposure of data element to wrong session vulnerability in Apache APISIX. This issue affects Apache APISIX: from 2.3.0 before 3.7.0. Under a supported authz-keycloak configuration, a request's authorization scope could persist into later requests on the same route, leading to unintended authorization expansion and… |