Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.46% | — | Cesanta MongooseAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in Cesanta Mongoose up to 7.21. Affected by this vulnerability is the function fn of the file tutorials/mqtt/mqtt-server/main.c of the component MQTT Broker. Executing a manipulation can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.57% | — | Cesanta MJSAI | 8/9/2026 | 8/9/2026 | A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was… | |
| Analizada | Media (5.4) | 0.41% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment using MG_ENABLE_DIRLIST and persuade a user to visit it. The mg_http_serve_dir() and listdir() path in src/http.c places the decoded request URI into the title and h1… | |
| Analizada | Media (6.5) | 0.46% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart input processed by mg_http_next_multipart() in src/http.c. The loops comparing s[b] and s[b + 1], and s[h2] and s[h2 + 1], use an incorrect AND condition and stop when… | |
| Analizada | Crítica (9.1) | 0.67% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in src/http.c accept both headers and… | |
| Analizada | Crítica (9.1) | 0.44% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests hm.proto.len with an impossible… | |
| Analizada | Media (6.5) | 0.66% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences in an #include file or #include virtual directive. The mg_ssi() function in src/ssi.c concatenates the directive argument into a filesystem path without calling… | |
| Analizada | Media (5.4) | 0.34% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger stored cross-site scripting when a user browses a directory served with MG_ENABLE_DIRLIST. The printdirentry() path called by listdir() in src/http.c URL-encodes the… | |
| Analizada | Crítica (9.1) | 0.34% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and mg_tls_verify_cert_cn() functions in src/tls_builtin.c… | |
| Analizada | Crítica (9.3) | 0.19% | — | Cesanta Mongoose | 20/8/2026 | 29/9/2026 | Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der while tls->ca_der.len remains zero, and… | |
| Aplazada | Alta (8.7) | 0.61% | — | Cesanta MongooseAI | 9/7/2026 | 29/8/2026 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello as a buffer index without validating it against the length of received data. A remote, unauthenticated attacker can… | |
| Analizada | Baja (2.9) | 0.25% | — | Cesanta Mongoose | 25/4/2026 | 17/6/2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This issue affects the function mg_aes_gcm_decrypt of the file /src/tls_aes128.c of the component GCM Authentication Tag Handler. Such manipulation leads to improper verification of cryptographic signature. The attack may be performed from… | |
| Analizada | Media (5.5) | 0.92% | — | Cesanta Mongoose | 25/4/2026 | 17/6/2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP Option Handler. This manipulation of the argument optlen causes infinite loop. The attack is possible to be carried out remotely. The exploit has been… | |
| Analizada | Baja (2.9) | 0.57% | — | Cesanta Mongoose | 2/4/2026 | 17/6/2026 | A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. Attacks of this nature are highly… | |
| Analizada | Baja (2.9) | 0.62% | — | Cesanta Mongoose | 2/4/2026 | 17/6/2026 | A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the argument buf results in stack-based buffer overflow. Remote exploitation of the attack is possible. A high degree of… | |
| Analizada | Media (5.5) | 0.76% | — | Cesanta Mongoose | 2/4/2026 | 17/6/2026 | A vulnerability has been found in Cesanta Mongoose up to 7.20. This affects the function mg_tls_recv_cert of the file mongoose.c of the component TLS 1.3 Handler. Such manipulation of the argument pubkey leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.9) | 0.27% | — | Cesanta Mongoose | 23/2/2026 | 17/6/2026 | A vulnerability was detected in Cesanta Mongoose up to 7.20. This impacts the function mg_chacha20_poly1305_decrypt of the file /src/tls_chacha20.c of the component Poly1305 Authentication Tag Handler. The manipulation results in improper verification of cryptographic signature. The attack may be launched remotely.… | |
| Analizada | Baja (2.9) | 0.70% | — | Cesanta Mongoose | 23/2/2026 | 17/6/2026 | A security vulnerability has been detected in Cesanta Mongoose up to 7.20. This affects the function getpeer of the file /src/net_builtin.c of the component TCP Sequence Number Handler. The manipulation leads to improper verification of source of a communication channel. The attack may be initiated remotely. The… | |
| Analizada | Baja (2.9) | 0.54% | — | Cesanta Mongoose | 23/2/2026 | 17/6/2026 | A weakness has been identified in Cesanta Mongoose up to 7.20. The impacted element is the function mg_sendnsreq of the file /src/dns.c of the component DNS Transaction ID Handler. Executing a manipulation of the argument random can lead to insufficiently random values. The attack can be launched remotely. The attack… | |
| Analizada | Media (4.3) | 0.29% | — | Cesanta Mongoose | 24/11/2025 | 17/6/2026 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of service via TLS initialization where SSL_CTX_get_cert_store() returns NULL. | |
| Analizada | Alta (7.5) | 0.43% | — | Cesanta Mongoose | 29/9/2025 | 17/6/2026 | An integer overflow vulnerability exists in the WebSocket component of Mongoose 7.5 thru 7.17. By sending a specially crafted WebSocket request, an attacker can cause the application to crash. If downstream vendors integrate this component improperly, the issue may lead to a buffer overflow. | |
| Aplazada | Media (5.3) | 0.36% | — | Cesanta FrozenAI | 27/1/2025 | 17/6/2026 | A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input. | |
| Aplazada | Media (5.3) | 0.36% | — | Cesanta FrozenAI | 27/1/2025 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input. | |
| Modificada | Alta (7.5) | 0.23% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters. | |
| Modificada | Media (5.3) | 0.28% | — | Cesanta Mongoose | 18/11/2024 | 8/9/2026 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space. |