Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)——Apache HttpdAI1/10/20261/10/2026
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
AplazadaMedia (5.3)0.21%—HttpdbgAI28/9/202630/9/2026
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured…
AplazadaBaja (2.1)0.24%—Fast Fac1900rAIUhttpdAI23/9/202624/9/2026
A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted…
Pendiente de análisisMedia (6.5)0.27%—Busybox HttpdAI23/9/202625/9/2026
BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.
Pendiente de análisisMedia (5.3)0.24%—Busybox HttpdAI23/9/202625/9/2026
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
Pendiente de análisisMedia (6.5)0.32%—Apache HttpdAIDogtag Certificate AuthorityAIRedhat Identity ManagementAI1/9/20261/9/2026
An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion…
AplazadaCrítica (9.3)0.93%—Openwrt UhttpdAI25/8/20263/9/2026
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By submitting a specially crafted username…
AplazadaAlta (7.5)0.58%—Acme Mini HttpdAI17/8/20269/9/2026
An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_request() function
AplazadaCrítica (9.1)0.44%—LighttpdAIUnknown Vendor Product FirmwareAI4/8/20269/9/2026
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
AplazadaCrítica (9.1)0.44%—LighttpdAI4/8/20269/9/2026
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
AplazadaAlta (7.4)0.79%—Wavlink Wn572AIWavlink Wn570hAIWavlink Wn573AIWavlink Wn529AI+83/8/202612/8/2026
A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551, WN557 and NU516 up to 20260609. Affected by this issue is the function strcpy of the file upload.cgi of the component lighttpd. The manipulation of the argument…
AplazadaAlta (8.9)1.1%—Totolink Nr1800xAILighttpdAI14/7/202615/7/2026
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit…
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by…
AplazadaAlta (8.9)1.0%—Totolink Nr1800xAILighttpdAI1/5/202617/6/2026
A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. The impacted element is the function find_host_ip of the component lighttpd. Such manipulation of the argument Host leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly…
AplazadaCrítica (9.8)0.69%—LighttpdAI9/2/202617/6/2026
An unauthenticated remote attacker can send a crafted HTTP request containing an overly long SESSIONID cookie. This can trigger a stack buffer overflow in the modified lighttpd server, causing it to crash and potentially enabling remote code execution due to missing stack protections.
AplazadaAlta (8.5)0.13%—Httpdebugger PROAI15/1/202617/6/2026
HTTPDebuggerPro 9.11 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables and gain elevated access to the system.
AnalizadaAlta (8.7)0.43%—GNU Libmicrohttpd10/11/202517/6/2026
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
AnalizadaAlta (8.7)0.43%—GNU Libmicrohttpd10/11/202517/6/2026
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
AnalizadaMedia (6.9)0.34%—Lighttpd3/11/202517/6/2026
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smuggling attacks. Successful exploitation may allow an attacker to: This issue affects lighttpd1.4.80
AplazadaAlta (8.7)2.1%—HttpdasmAI23/7/202516/6/2026
A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthenticated attackers to read arbitrary files on the host system. By sending a specially crafted GET request containing a sequence of URL-encoded backslashes and directory traversal patterns, an attacker…
AplazadaCrítica (9.3)4.5%—LighttpdAIDlink Dsp-w110a1AI16/7/202517/6/2026
An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1 firmware version 1.05B01. This occurs when specially crafted cookie values are processed, allowing remote attackers to execute arbitrary commands on the underlying Linux operating…
AplazadaAlta (7.7)0.29%—LighttpdAI25/4/202517/6/2026
The device exposes a web interface on ports TCP/3030 and TCP/9882. This web service runs lighttpd, which implements the “SNORE” interface. This interface is affected by a stack buffer overflow vulnerability due to insecure path parsing. An attacker with access to the LAN network interface could use a specially crafted…
AplazadaAlta (7.1)0.39%—Trendnet Ti-g102iAILighttpdAI30/3/202517/6/2026
A vulnerability was found in TRENDnet TI-G102i 1.0.7.S0_ /1.0.8.S0_ and classified as problematic. This issue affects the function plugins_call_handle_uri_raw of the file /usr/sbin/lighttpd of the component HTTP Request Handler. The manipulation leads to null pointer dereference. The attack can only be done within the…
AplazadaMedia (5.3)0.44%—AtophttpdAI26/3/202517/6/2026
httpd.c in atophttpd 2.8.0 has an off-by-one error and resultant out-of-bounds read because a certain 1024-character req string would not have a final '\0' character.
AplazadaMedia (5.3)0.67%—LighttpdAI17/6/202417/6/2026
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from other requests.