Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.58% | — | Acme Mini HttpdAI | 17/8/2026 | 9/9/2026 | An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function | |
| Aplazada | Media (5.3) | 0.29% | — | Acmethemes Education BaseAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in acmethemes Education Base education-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Education Base: from n/a through <= 3.0.8. | |
| Aplazada | Media (6.5) | 0.29% | — | Acmeit TAG Category Taxonomy ManagerAI | 6/12/2025 | 17/6/2026 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'existing_terms_orderby' parameter in the AI preview AJAX endpoint in all versions up to, and including, 3.40.1. This is due to insufficient escaping on user-supplied… | |
| Aplazada | Baja (2.3) | 0.22% | — | Go-acme LegoAI | 7/8/2025 | 17/6/2026 | Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike the http-01 challenge which solves an ACME challenge over… | |
| Aplazada | Alta (7.1) | 0.12% | — | Acmeedesign WpshapereAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere - WordPress admin theme wpshapere-lite allows Stored XSS.This issue affects WPShapere - WordPress admin theme: from n/a through <= 1.4.1. | |
| Aplazada | Alta (8.7) | 0.40% | — | Acme.shAI | 4/4/2025 | 17/6/2026 | The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout. | |
| Aplazada | Media (4.3) | 0.30% | — | Acmemediakits Acme-divi-modulesAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in acmemediakits ACME Divi Modules acme-divi-modules allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACME Divi Modules: from n/a through <= 1.3.5. | |
| Aplazada | Alta (7.1) | 0.37% | — | Xdxdvsxdxd MacmeAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xdxdVSxdxd MACME macme allows Reflected XSS.This issue affects MACME: from n/a through <= 1.2. | |
| Aplazada | Media (4.3) | 0.34% | — | Acme Themes Acme FIX ImagesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Acme Themes Acme Fix Images acme-fix-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acme Fix Images: from n/a through <= 1.0.0. | |
| Modificada | Alta (7.5) | 1.4% | — | Acme Ultra Mini Httpd | 7/1/2024 | 17/6/2026 | A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 1.1% | — | Acme.sh Project Acme.sh | 13/7/2023 | 17/6/2026 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023. | |
| Modificada | Crítica (9.6) | 0.67% | — | Netgate PfsenseNetgate Pfsense Acme Package | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php. | |
| Modificada | Media (6.1) | 0.63% | — | Netgate AcmeNetgate Pfsense | 15/12/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package. | |
| Modificada | Crítica (9.8) | 1.3% | — | Acme Thttpd | 27/12/2019 | 16/6/2026 | thttpd 2007 has buffer underflow. | |
| Modificada | Media (5.5) | 0.39% | — | Acme Thttpd | 25/11/2019 | 16/6/2026 | thttpd has a local DoS vulnerability via specially-crafted .htpasswd files | |
| Modificada | Media (6.5) | 71% | — | Acme Mini-httpd | 29/10/2018 | 17/6/2026 | ACME mini_httpd before 1.30 lets remote users read arbitrary files. | |
| Modificada | Crítica (9.8) | 2.7% | — | Acme Mini HttpdAcme Thttpd | 6/2/2018 | 17/6/2026 | The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. | |
| Modificada | Media (5) | 1.6% | — | Acme Mini Httpd | 10/2/2015 | 17/6/2026 | mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read. | |
| Modificada | Alta (7.8) | 11% | — | Acme Micro HttpdDlink Dsl2740uDlink Dsl2750uNetgear Mr-adsl-dg834+1 | 24/7/2014 | 17/6/2026 | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request. | |
| Modificada | Baja (2.1) | 0.52% | — | Open Source Development Team SthttpdFedoraproject FedoraGentoo LinuxOpensuse+1 | 13/12/2013 | 16/6/2026 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Media (5) | 2.6% | — | Acme Micro HttpdRCA Digital Cable Modem | 26/4/2010 | 16/6/2026 | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | |
| Modificada | Crítica (9.8) | 14% | — | Acme Thttpd | 13/1/2010 | 16/6/2026 | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 10% | — | Acme Mini Httpd | 13/1/2010 | 16/6/2026 | mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 2.9% | — | Acme Labs Thttpd | 2/2/2007 | 16/6/2026 | thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.2) | 0.38% | — | Acme Labs Thttpd | 31/10/2006 | 16/6/2026 | thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. |