Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.1% | — | Hiawatha-webserver HiawathaAI | 31/7/2026 | 31/8/2026 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request | |
| Analizada | Media (6.5) | 0.38% | — | Hiawatha.leisink Hiawatha Webserver | 26/1/2026 | 17/6/2026 | A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution. | |
| Analizada | Baja (3.3) | 0.16% | — | Hiawatha-webserver Hiawatha | 26/1/2026 | 17/6/2026 | Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client. | |
| Analizada | Media (5.3) | 0.48% | — | Hiawatha-webserver Hiawatha | 26/1/2026 | 17/6/2026 | Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver. | |
| Modificada | Alta (8.1) | 1.5% | — | Hiawatha-webserver Hiawatha | 16/2/2019 | 17/6/2026 | In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled. |