Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
559 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 42% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Analizada | Crítica (9.1) | 100% | ⚠ Explotación activa | Apache Http ServerNetapp Ontap 9Sonicwall SMA 200 FirmwareSonicwall SMA 210 Firmware+3 | 1/7/2024 | 17/6/2026 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in… | |
| Modificada | Crítica (9.8) | 2.5% | — | Apache Http ServerNetapp Clustered Data Ontap | 1/7/2024 | 17/6/2026 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version… | |
| Analizada | Alta (8.1) | 26% | — | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue. | |
| Analizada | Alta (7.5) | 69% | — | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to… | |
| Analizada | Media (5.4) | 1.7% | — | Apache Http ServerNetapp Ontap | 1/7/2024 | 17/6/2026 | Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. | |
| Analizada | Media (5.3) | 0.57% | — | Oracle Http Server | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this… | |
| Aplazada | Alta (7.5) | 0.79% | — | Micrium OS Network Http ServerAI | 16/4/2024 | 17/6/2026 | A bug in Micrium OS Network HTTP Server permits an invalid pointer dereference during header processing - potentially allowing a device crash and Denial of Service. | |
| Modificada | Alta (7.5) | 91% | — | Apache Http ServerFedoraproject FedoraNetapp Ontap | 4/4/2024 | 17/6/2026 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. | |
| Analizada | Media (6.3) | 2.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue. | |
| Modificada | Alta (7.3) | 3.9% | — | Apache Http ServerDebian LinuxFedoraproject FedoraNetapp Ontap+3 | 4/4/2024 | 17/6/2026 | Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58. | |
| Modificada | Alta (7.5) | 1.3% | — | Karjasoft Sami Http Server | 18/1/2024 | 17/6/2026 | A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 1.6% | — | Alekseykurepin Pico Http Server IN C | 5/1/2024 | 17/6/2026 | route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution. | |
| Modificada | Media (4.6) | 0.29% | — | Fedirtsapana Simple Http Server Plus | 27/12/2023 | 17/6/2026 | Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device. | |
| Modificada | Media (6.3) | 0.12% | — | Fedirtsapana Simple Http ServerFedirtsapana Simple Http Server Plus | 27/12/2023 | 17/6/2026 | Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS… | |
| Modificada | Crítica (9.8) | 0.70% | — | Starnight Micro Http Server | 25/12/2023 | 17/6/2026 | In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Starnight Micro Http Server | 17/12/2023 | 17/6/2026 | In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based buffer overflow and potentially remote code execution via a long URI. | |
| Analizada | Media (5.9) | 3.0% | — | Apache Http ServerFedoraproject FedoraDebian Linux | 23/10/2023 | 17/6/2026 | When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the request's memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint… | |
| Modificada | Alta (7.5) | 71% | — | Apache Http Server | 23/10/2023 | 17/6/2026 | An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern. This has been fixed in version 2.4.58, so… | |
| Analizada | Alta (7.5) | 3.0% | — | Debian LinuxApache Http ServerFedoraproject Fedora | 23/10/2023 | 17/6/2026 | Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57. | |
| Modificada | Alta (7.5) | 0.51% | — | Oracle Http Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.5) | 0.92% | — | IBM Http Server | 30/5/2023 | 17/6/2026 | IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 255828. | |
| Modificada | Media (6.1) | 0.62% | — | Dart Http Server | 10/4/2023 | 17/6/2026 | A vulnerability was found in Dart http_server up to 0.9.5 and classified as problematic. Affected by this issue is the function VirtualDirectory of the file lib/src/virtual_directory.dart of the component Directory Listing Handler. The manipulation of the argument request.uri.path leads to cross site scripting. The… | |
| Analizada | Alta (7.5) | 2.1% | — | Apache Http ServerDebian LinuxUnbit Uwsgi | 7/3/2023 | 17/6/2026 | HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client. |