Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.55% | — | TinywebAI | 28/7/2026 | 30/7/2026 | TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without normalization, dot-segment removal, or boundary… | |
| Aplazada | Alta (8.7) | 0.61% | — | TinywebAI | 28/7/2026 | 30/7/2026 | TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url object when version parsing fails, leaving… | |
| Aplazada | Alta (8.7) | 0.51% | — | TinywebAI | 28/7/2026 | 30/7/2026 | TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader instances via raw new expressions that are… | |
| Aplazada | Media (6.4) | 0.26% | — | Tinywebgallery Advanced IframeAI | 8/7/2026 | 8/7/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (5.5) | 0.32% | — | Ritlabs Tinyweb ServerAI | 15/6/2026 | 24/7/2026 | A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack can be initiated remotely. The… | |
| Analizada | Crítica (9.2) | 0.56% | — | Ritlabs Tinyweb | 6/3/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characters in header lines and header values, including CR, LF, and NUL, and… | |
| Analizada | Crítica (9.3) | 0.67% | — | Ritlabs Tinyweb | 6/3/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrictions and perform HTTP Request Smuggling. This can lead to… | |
| Analizada | Alta (8.7) | 0.82% | — | Ritlabs Tinyweb | 26/2/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticated remote attackers can send an HTTP POST request to the server with an exceptionally large `Content-Length` header (e.g., `2147483647`).… | |
| Analizada | Alta (8.7) | 0.82% | — | Ritlabs Tinyweb | 26/2/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server spawns a new OS thread for every incoming connection without enforcing a maximum concurrency limit or an appropriate request timeout. An… | |
| Analizada | Crítica (10) | 1.4% | — | Ritlabs Tinyweb | 25/2/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server configuration and the specific CGI executable in use, the impact is either source code… | |
| Aplazada | Media (6.5) | 0.23% | — | Tinywebgallery Advanced IframeAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10. | |
| Analizada | Crítica (10) | 2.5% | — | Ritlabs Tinyweb | 12/1/2026 | 17/6/2026 | TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows CreateProcess(). An unauthenticated remote… | |
| Analizada | Media (5.1) | 0.24% | — | Tinywebgallery | 18/12/2025 | 17/6/2026 | TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages. | |
| Analizada | Crítica (9.3) | 1.1% | — | Tinywebgallery | 17/12/2025 | 17/6/2026 | TinyWebGallery v2.5 contains a remote code execution vulnerability in the admin upload functionality that allows unauthenticated attackers to upload malicious PHP files. Attackers can upload .phar files with embedded system commands to execute arbitrary code on the server by accessing the uploaded file's URL. | |
| Aplazada | Media (5.4) | 0.24% | — | Tinywebgallery Advanced IframeAI | 16/8/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.4) | 0.30% | — | Tinywebgallery Advanced IframeAI | 26/7/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Analizada | Media (6.9) | 0.77% | — | Qinguoyi Tinywebserver | 4/4/2025 | 17/6/2026 | A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.53% | — | Qinguoyi Tinywebserver | 4/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.80% | — | Qinguoyi Tinywebserver | 4/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to stack-based buffer overflow. The attack may be launched remotely. The… | |
| Analizada | Media (5.3) | 0.29% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData… | |
| Analizada | Media (5.4) | 0.21% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied… | |
| Modificada | Media (5.4) | 0.26% | — | Tinywebgallery Advanced Iframe | 26/3/2025 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.34% | — | Tinywebgallery Advanced IframeAI | 23/5/2024 | 17/6/2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Modificada | Media (5.5) | 0.66% | — | Ritlabs Tinyweb | 22/5/2024 | 17/6/2026 | A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. The manipulation with the input %0D%0A leads to crlf injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.… | |
| Modificada | Alta (8.6) | 1.2% | — | Ritlabs Tinyweb | 14/5/2024 | 17/6/2026 | TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line. |