Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2807▲ 74 respecto a la semana anterior
Críticas / altas1475▲ 313 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.8)0.35%—Guzzlehttp Guzzle ServicesAI11/6/202617/6/2026
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model structures. Versions prior ro 1.5.4 do not safely serialize scalar XML element values containing the CDATA terminator…
ModificadaMedia (5.5)0.36%—Hashicorp Retryablehttp24/6/202417/6/2026
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.
ModificadaAlta (7.5)0.74%—Hongliuliao Ehttp31/12/202317/6/2026
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
ModificadaAlta (7.5)0.74%—Hongliuliao Ehttp31/12/202317/6/2026
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
ModificadaMedia (5.3)1.3%—Simplehttpserver Project Simplehttpserver4/12/201817/6/2026
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
ModificadaAlta (7.5)2.0%—Simplehttpserver Project Simplehttpserver31/8/201817/6/2026
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
ModificadaMedia (5.4)0.64%—Simplehttpserver Project Simplehttpserver7/6/201817/6/2026
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModificadaAlta (7.5)6.4%—Frank Yaul Corehttp8/12/200916/6/2026
Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2007-4060.
ModificadaAlta (9)5.4%—Frank Yaul Corehttp30/7/200716/6/2026
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code via a long string in the (1) method name or (2) URI in an HTTP request.