Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
1205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.52% | — | WosdefaulthttpmoduleAI | 27/5/2026 | 17/6/2026 | A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome | |
| Aplazada | Alta (7.5) | 0.50% | — | WosdefaulthttpmoduleAI | 27/5/2026 | 17/6/2026 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome | |
| Aplazada | Alta (7.5) | 0.46% | — | WOS Http Status ModuleAI | 27/5/2026 | 17/6/2026 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would be called to set up a "module" object for that module. However, WOSHttpStatusModule.dll is not present in the… | |
| Aplazada | Crítica (9.1) | 2.6% | — | Perl Http DaemonAI | 27/5/2026 | 23/7/2026 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a subprocess, '> path' and '>> path' open the path for write or append. Untrusted input… | |
| Modificada | Crítica (9.8) | 0.86% | — | IBM Http Server | 26/5/2026 | 20/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service and a potential remote code execution due to improper input validation. | |
| Analizada | Crítica (9.1) | 0.34% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration. | |
| Analizada | Crítica (9.8) | 0.85% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication). | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. | |
| Analizada | Alta (7.3) | 0.31% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service. | |
| Analizada | Alta (8) | 0.34% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service. | |
| Analizada | Alta (7.5) | 0.33% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Http Server | 26/5/2026 | 23/7/2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. | |
| Aplazada | Alta (8.7) | 7.8% | — | Openwrt Luci-app-https-dns-proxyAI | 26/5/2026 | 24/7/2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the… | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | Checkpoint Http-based ServiceAI | 26/5/2026 | 24/7/2026 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. | |
| Aplazada | Alta (7.3) | 0.52% | — | GohttpAI | 19/5/2026 | 24/7/2026 | An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request. | |
| Aplazada | Media (4.7) | 0.20% | — | Python-utcp Utcp-httpAI | 14/5/2026 | 17/6/2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency between manual discovery and tool invocation. register_manual() validates the discovery URL against an HTTPS / loopback allowlist,… | |
| Aplazada | Media (6.5) | 0.36% | — | Perl Http TinyAI | 11/5/2026 | 17/6/2026 | HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method and URI in the request line, the URL host that becomes the `Host:` header, and HTTP/1.1 control data field values. An attacker who controls one of these inputs, for… | |
| Aplazada | Alta (8.2) | 0.44% | — | I18next-http-middlewareAI | 8/5/2026 | 17/6/2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware passes the user-controlled lng and ns values from getResourcesHandler directly into i18next.services.backendConnector.load(languages, namespaces, …)… | |
| Aplazada | Alta (8.6) | 0.47% | — | 18next Http-middlewareAINodejsAIExpressAIFastifyAI+1 | 8/5/2026 | 17/6/2026 | 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal… | |
| Aplazada | Alta (8.6) | 0.40% | — | I18next-http-middlewareAII18nextAI | 8/5/2026 | 17/6/2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Prior to version 3.9.3, i18next-http-middleware wrote user-controlled language values into the Content-Language response header after passing them through utils.escape(), which is an HTML-entity… | |
| Analizada | Crítica (9.1) | 0.39% | — | I18next-http-backend | 7/5/2026 | 17/6/2026 | Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3.0.5 interpolate the lng and ns values directly into the configured loadPath / addPath URL template without any… | |
| Modificada | Alta (7.5) | 0.78% | — | Golang GOGolang Http2 | 7/5/2026 | 18/9/2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0. | |
| Modificada | Crítica (9.8) | 1.6% | — | Apache Http Server | 5/5/2026 | 14/9/2026 | Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache… | |
| Analizada | Alta (7.3) | 1.1% | — | Apache Http Server | 5/5/2026 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. | |
| Analizada | Media (6.5) | 0.44% | — | Apache Http Server | 4/5/2026 | 17/6/2026 | HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue. |