Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
1204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.53% | — | AiohttpAI | 3/8/2026 | 10/9/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the… | |
| Pendiente de análisis | Media (6.3) | 0.44% | — | AiohttpAI | 3/8/2026 | 10/9/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in… | |
| Aplazada | Alta (7.4) | 0.79% | — | Wavlink Wn572AIWavlink Wn570hAIWavlink Wn573AIWavlink Wn529AI+8 | 3/8/2026 | 12/8/2026 | A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument… | |
| Pendiente de análisis | Media (6.8) | 0.41% | — | Luci-app-https-dns-proxyAI | 1/8/2026 | 8/9/2026 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser… | |
| Modificada | Media (5.3) | 0.46% | — | Apache Httpclient | 31/7/2026 | 13/8/2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue… | |
| Aplazada | Media (6.1) | 0.34% | — | Adonisjs Http ServerAI | 30/7/2026 | 10/9/2026 | AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled… | |
| Aplazada | Media (6.9) | 0.52% | — | AiohttpAI | 30/7/2026 | 30/7/2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause unexpected CPU and memory consumption. This… | |
| Aplazada | Media (6.3) | 0.41% | — | RouilleAITiny-http Tiny HttpAI | 28/7/2026 | 30/7/2026 | Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's Transfer-Encoding header to upstream backends… | |
| Aplazada | Media (6.3) | 0.30% | — | Tiny-httpAI | 28/7/2026 | 30/7/2026 | tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient validation in header parsing and serialization. Attackers can exploit this injection… | |
| Aplazada | Media (6.3) | 0.33% | — | Tiny-httpAI | 28/7/2026 | 30/7/2026 | tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply chunk-decoding and discard Content-Length.… | |
| Aplazada | Alta (7.8) | 0.66% | — | MispAIApache Http ServerAI | 28/7/2026 | 30/7/2026 | MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect permanent / https://misp.example Apache’s Redirect directive appends any portion of the requested path that follows the matched prefix to the configured destination URL.… | |
| Analizada | Media (5.3) | 0.29% | — | Apple Swiftnio Http/2 | 23/7/2026 | 1/9/2026 | SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0. | |
| Pendiente de análisis | Alta (8.7) | 0.75% | — | Amazon Aws-smithy-http-serverAI | 23/7/2026 | 12/8/2026 | Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Http Server | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_http2.so). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Http Server | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Http Server | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_ssl). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of… | |
| Analizada | Alta (8.6) | 0.44% | — | Oracle Http Server | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. While the vulnerability… | |
| Analizada | Crítica (10) | 0.43% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 21/7/2026 | 5/8/2026 | Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Http Server | 21/7/2026 | 1/8/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Apache Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks… | |
| Analizada | Crítica (10) | 0.44% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a literal string replace against the… | |
| Analizada | Crítica (10) | 0.50% | — | Fastify/http-proxy | 18/7/2026 | 28/7/2026 | Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapses dot segments, so… | |
| Aplazada | Alta (7.5) | 0.63% | — | Http DateAI | 17/7/2026 | 12/8/2026 | HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next to each other before a trailing `\s*$`… | |
| Aplazada | Alta (8.9) | 1.1% | — | Totolink Nr1800xAILighttpdAI | 14/7/2026 | 15/7/2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit… | |
| Analizada | Alta (7.4) | 0.26% | — | Yhirose Cpp-httplib | 10/7/2026 | 14/7/2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions from 0.31.0 through 0.46.1 and wolfSSL backend versions from 0.33.0 through 0.46.1, when cpp-httplib is built with CPPHTTPLIB_MBEDTLS_SUPPORT or CPPHTTPLIB_WOLFSSL_SUPPORT and a client connects to an… |