Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3042▲ 436 respecto a la semana anterior
Críticas / altas1431▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 168 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.15%—Smallsrv Small Http Server26/3/202617/6/2026
Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher priority directory, causing…
AnalizadaAlta (8.7)0.61%—Smallsrv Small Http Server26/3/202617/6/2026
Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the server.
ModificadaCrítica (9.8)2.3%—Smallsrv Small Http Server29/4/202217/6/2026
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http ServerVwebserver29/6/200116/6/2026
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http Server27/6/200116/6/2026
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
ModificadaMedia (5)1.2%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
ModificadaMedia (5)3.3%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.
ModificadaMedia (5)1.3%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.
ModificadaMedia (5)6.5%—MAX Feoktistov Small Http Server15/6/200016/6/2026
Small HTTP Server ver 3.06 contains a memory corruption bug causing a memory overflow. The overflowed buffer crashes into a Structured Exception Handler resulting in a Denial of Service.