Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Cesanta Mongoose | 7/11/2017 | 17/6/2026 | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to… | |
| Modificada | Alta (8.8) | 4.1% | 💥 Exploit | Cesanta Mongoose Embedded WEB Server Library | 7/9/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Cesanta Mongoose Embedded WEB Server LibraryCesanta Mongoose OS | 10/4/2017 | 17/6/2026 | Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary… | |
| Modificada | Alta (7.8) | 2.0% | — | Erlang-solutions Mongooseim | 11/4/2014 | 17/6/2026 | Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | ShttpdValenok MongooseYasslews | 5/8/2011 | 16/6/2026 | Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as… | |
| Modificada | Media (5) | 6.7% | 💥 Exploit | Valenok Mongoose | 31/12/2009 | 16/6/2026 | Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI. | |
| Modificada | Media (5) | 1.2% | — | Sergey Lyubka Mongoose | 31/12/2009 | 16/6/2026 | Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | Sergey Lyubka Mongoose | 21/4/2009 | 16/6/2026 | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Alta (7.5) | 1.4% | — | Goosequill Audienceconnect Secureeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. | |
| Modificada | Alta (7.5) | 1.4% | — | Goosequill Audienceconnect Remoteeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions. | |
| Modificada | Alta (10) | 1.7% | — | Goosequill Remoteeditor | 31/12/2004 | 16/6/2026 | Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions." | |
| Modificada | Alta (10) | 1.4% | — | Goosequill Audienceconnect | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors. |