Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)0.63%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected…
AplazadaAlta (8.7)0.58%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from…
AplazadaAlta (8.3)0.52%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring…
AplazadaAlta (8.3)0.58%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before…
AplazadaAlta (8.2)0.93%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive. mod_auth:secret_path/3 decides whether a resolved…
AplazadaMedia (6.3)0.58%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits. httpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1…
AplazadaAlta (8.7)0.67%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete. httpd_request_handler:handle_info/2 cancels the…
AplazadaAlta (8.7)0.93%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents…
AplazadaAlta (8.2)0.97%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash. httpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986…
AplazadaAlta (8.3)0.58%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved. This issue affects OTP from OTP…
AplazadaAlta (8.2)0.69%—Erlang OTPAIErlang InetsAI1/9/20268/9/2026
The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF…
AplazadaAlta (8.7)0.95%—Erlang OTPAIErlang InetsAI1/9/202622/9/2026
Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no…
ModificadaMedia (6.3)0.23%—Erlang/inetsErlang/otpErlang FTP10/6/202624/7/2026
Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts the IP address from the server's 227…
ModificadaAlta (7.1)0.34%—Erlang/inetsErlang/otp10/6/202624/9/2026
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2…
ModificadaAlta (8.3)0.77%—Erlang/inetsErlang/otp7/4/20268/9/2026
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the…
ModificadaAlta (7)0.45%—Erlang/inetsErlang/otp13/3/202624/7/2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. The server does not…
AplazadaBaja (2.3)0.48%—Erlang OTPAIErlang InetsAIErlang TftpAI20/2/202624/7/2026
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl,…
ModificadaMedia (6.1)0.91%—Inetsoftware I-net Clear Reports9/3/202117/6/2026
I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.
ModificadaCrítica (9.8)1.1%—Inetsoftware I-net Clear Reports15/7/202017/6/2026
XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a reference to an external entity is processed by a weakly configured XML parser.
ModificadaCrítica (9.1)2.1%—Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc7/5/202017/6/2026
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
ModificadaMedia (5)1.6%—Inetstore Online9/1/200616/6/2026
Cross-site scripting vulnerability search.inetstore in iNETstore Ebusiness Software 2.0 allows remote attackers to inject arbitrary web script or HTML via the searchterm parameter.
ModificadaMedia (4.3)1.2%—Infinetsoftware Mytemplatesite5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)2.6%—Avtronics Inetserv22/8/200116/6/2026
Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.
ModificadaAlta (10)13%—Avtronics Inetserv17/1/200016/6/2026
Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request.