Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—Cesanta Mongoose7/11/201717/6/2026
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send this HTTP request over the network to…
ModificadaAlta (8.8)4.1%💥 ExploitCesanta Mongoose Embedded WEB Server Library7/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.
ModificadaAlta (7.5)12%💥 ExploitCesanta Mongoose Embedded WEB Server LibraryCesanta Mongoose OS10/4/201717/6/2026
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary…
ModificadaAlta (7.8)2.0%—Erlang-solutions Mongooseim11/4/201417/6/2026
Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.
ModificadaAlta (7.5)13%💥 ExploitShttpdValenok MongooseYasslews5/8/201116/6/2026
Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as…
ModificadaMedia (5)6.7%💥 ExploitValenok Mongoose31/12/200916/6/2026
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
ModificadaMedia (5)1.2%—Sergey Lyubka Mongoose31/12/200916/6/2026
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.
ModificadaMedia (4)2.3%💥 ExploitSergey Lyubka Mongoose21/4/200916/6/2026
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaAlta (7.5)1.4%—Goosequill Audienceconnect Secureeditor31/12/200416/6/2026
Unknown vulnerability in the "access code" in SecureEditor before 0.1.2 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.
ModificadaAlta (7.5)1.4%—Goosequill Audienceconnect Remoteeditor31/12/200416/6/2026
Unknown vulnerability in the "access code" in RemoteEditor before 0.1.6 has unknown impact and attack vectors, possibly involving a bypass of IP address restrictions.
ModificadaAlta (10)1.7%—Goosequill Remoteeditor31/12/200416/6/2026
Unknown vulnerability in RemoteEditor before 0.1.1 has unknown impact and attack vectors, related to "oversize submissions."
ModificadaAlta (10)1.4%—Goosequill Audienceconnect31/12/200416/6/2026
Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.
Orbitaley — Vulnerabilidades