Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.52% | — | EspasynchttpserverAI | 17/9/2026 | 24/9/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly… | |
| Aplazada | Alta (8.7) | 0.43% | — | EspasynchttpserverAI | 27/6/2025 | 17/6/2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows… | |
| Modificada | Alta (7.5) | 0.88% | — | Httpserver Project Httpserver | 27/12/2022 | 17/6/2026 | A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The… | |
| Modificada | Media (5.3) | 1.6% | — | Statichttpserver Project Statichttpserver | 3/9/2019 | 17/6/2026 | A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders. | |
| Modificada | Media (5.3) | 1.3% | — | Simplehttpserver Project Simplehttpserver | 4/12/2018 | 17/6/2026 | A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root. | |
| Modificada | Alta (7.5) | 2.0% | — | Simplehttpserver Project Simplehttpserver | 31/8/2018 | 17/6/2026 | Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Cybrotech Cybrohttpserver | 29/8/2018 | 17/6/2026 | Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI. | |
| Modificada | Media (5.3) | 39% | 💥 Exploit | Cybrotech Cybrohttpserver | 29/8/2018 | 17/6/2026 | Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI. | |
| Modificada | Media (5.4) | 0.64% | — | Simplehttpserver Project Simplehttpserver | 7/6/2018 | 17/6/2026 | simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names. | |
| Modificada | Alta (7.5) | 2.8% | — | HP CompaqhttpserverHP System Management Homepage | 13/4/2006 | 16/6/2026 | HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL. | |
| Modificada | Media (4.3) | 0.97% | — | Compaqhttpserver | 20/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page. | |
| Modificada | Media (4.3) | 0.94% | — | Minihttpserver.net Forum WEB Server | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm. | |
| Modificada | Media (4.6) | 0.31% | — | Minihttpserver.net WEB Forums ServerAI | 31/12/2004 | 16/6/2026 | Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.5% | — | Minihttpserver.net WEB Forums Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash). | |
| Modificada | Media (5) | 1.4% | — | Geovision Geohttpserver | 31/12/2004 | 16/6/2026 | GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines). | |
| Modificada | Media (5) | 1.9% | — | Geovision Geohttpserver | 31/12/2004 | 16/6/2026 | The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. |