Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2807▲ 74 respecto a la semana anterior
Críticas / altas1475▲ 313 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.8) | 0.35% | — | Guzzlehttp Guzzle ServicesAI | 11/6/2026 | 17/6/2026 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do not safely serialize scalar XML element values containing the CDATA terminator… | |
| Modificada | Media (5.5) | 0.36% | — | Hashicorp Retryablehttp | 24/6/2024 | 17/6/2026 | go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7. | |
| Modificada | Alta (7.5) | 0.74% | — | Hongliuliao Ehttp | 31/12/2023 | 17/6/2026 | ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings. | |
| Modificada | Alta (7.5) | 0.74% | — | Hongliuliao Ehttp | 31/12/2023 | 17/6/2026 | ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this. | |
| Modificada | Media (5.3) | 1.3% | — | Simplehttpserver Project Simplehttpserver | 4/12/2018 | 17/6/2026 | A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. | |
| Modificada | Alta (7.5) | 2.0% | — | Simplehttpserver Project Simplehttpserver | 31/8/2018 | 17/6/2026 | Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server. | |
| Modificada | Media (5.4) | 0.64% | — | Simplehttpserver Project Simplehttpserver | 7/6/2018 | 17/6/2026 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | |
| Modificada | Alta (7.5) | 6.4% | — | Frank Yaul Corehttp | 8/12/2009 | 16/6/2026 | Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2007-4060. | |
| Modificada | Alta (9) | 5.4% | — | Frank Yaul Corehttp | 30/7/2007 | 16/6/2026 | Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code via a long string in the (1) method name or (2) URI in an HTTP request. |