Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)39%—Rejetto Http File Server4/7/202417/6/2026
rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js).
AnalizadaCrítica (9.8)99%⚠ Explotación activaRejetto Http File Server31/5/202411/8/2026
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m…
AplazadaAlta (7.1)0.24%—Cutesoft Cute Http File ServerAI19/4/202417/6/2026
CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.
ModificadaAlta (8.2)0.50%—Iscute Cute Http File Server7/3/20249/7/2026
An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.
ModificadaMedia (5.4)0.37%—Iscute Cute Http File Server20/12/202317/6/2026
Cross Site Scripting (XSS) vulnerability in CuteHttpFileServer v.1.0 and v.2.0 allows attackers to obtain sensitive information via the file upload function in the home page.
ModificadaMedia (6.1)0.52%—Iscute Cute Http File Server3/8/202317/6/2026
A vulnerability, which was classified as problematic, was found in Cute Http File Server 2.0. This affects an unknown part of the component Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (8.1)1.2%—Http File Server Project Http File Server9/6/202217/6/2026
The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.
ModificadaAlta (7.5)31%—Rejetto Http File Server8/6/202017/6/2026
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
ModificadaMedia (5.4)0.71%—Http-file-server Project Http-file-server30/7/201917/6/2026
Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server file system to execute arbitrary JavaScript code in victim's browser.
ModificadaMedia (5.3)1.5%—Http-file-server Project Http-file-server15/7/201917/6/2026
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
ModificadaAlta (7.5)9.2%—Rejetto Http File Server10/10/201417/6/2026
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.
AnalizadaCrítica (9.8)99%⚠ Explotación activaRejetto Http File Server7/10/201417/6/2026
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
ModificadaMedia (4.3)1.3%—HFS Http File Server29/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL.
ModificadaMedia (5)1.6%—HFS Http File Server29/1/200816/6/2026
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.
ModificadaMedia (6.4)1.7%—HFS Http File Server29/1/200816/6/2026
HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication.
ModificadaAlta (10)3.1%—HFS Http File Server29/1/200816/6/2026
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a ..…
ModificadaMedia (5)3.6%—HFS Http File Server29/1/200816/6/2026
HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.
ModificadaMedia (5)1.8%—HFS Http File Server29/1/200816/6/2026
HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL.