Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.52%—EspasynchttpserverAI17/9/202624/9/2026
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly…
AplazadaAlta (8.7)0.43%—EspasynchttpserverAI27/6/202517/6/2026
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows…
ModificadaAlta (7.5)0.88%—Httpserver Project Httpserver27/12/202217/6/2026
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The…
ModificadaMedia (5.3)1.6%—Statichttpserver Project Statichttpserver3/9/201917/6/2026
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
ModificadaMedia (5.3)1.3%—Simplehttpserver Project Simplehttpserver4/12/201817/6/2026
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
ModificadaAlta (7.5)2.0%—Simplehttpserver Project Simplehttpserver31/8/201817/6/2026
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
ModificadaMedia (6.1)4.0%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
ModificadaMedia (5.3)39%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
ModificadaMedia (5.4)0.64%—Simplehttpserver Project Simplehttpserver7/6/201817/6/2026
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModificadaAlta (7.5)2.8%—HP CompaqhttpserverHP System Management Homepage13/4/200616/6/2026
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
ModificadaMedia (4.3)0.97%—Compaqhttpserver20/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
ModificadaMedia (4.3)0.94%—Minihttpserver.net Forum WEB Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModificadaMedia (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI31/12/200416/6/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModificadaMedia (5)1.5%—Minihttpserver.net WEB Forums Server31/12/200416/6/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModificadaMedia (5)1.4%—Geovision Geohttpserver31/12/200416/6/2026
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
ModificadaMedia (5)1.9%—Geovision Geohttpserver31/12/200416/6/2026
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.
Orbitaley — Vulnerabilidades