Vulnerabilities

Summary — last 7 days

New vulnerabilities2,493▼ 464 vs. last week
Critical / high1,281▼ 12 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)60▼ 468 vs. last week
–

374 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.4)0.15%—Trendnet Tv-ip110wnAIBOA WEB ServerAI8/9/20256/17/2026
A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the file /server/boa.conf of the component Embedded Boa Web Server. The manipulation leads to least privilege violation. Local access is required to approach this attack. The…
DeferredCritical (9.3)1.7%—Simple WEB ServerAI8/8/20256/16/2026
Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer overflow on the stack. This flaw allows remote…
AnalyzedHigh (7.5)0.80%—Litespeedtech Litespeed WEB ADCLitespeedtech Litespeed WEB ServerLitespeedtech LsquicLitespeedtech Openlitespeed8/1/20256/17/2026
LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
DeferredHigh (8.7)1.7%—Dicoogle Pacs WEB ServerAI7/23/20256/17/2026
An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. The vulnerability allows remote attackers to read arbitrary files on the underlying system by sending a crafted request to the /exportFile endpoint using the UID parameter. Successful exploitation can…
AnalyzedHigh (7.4)0.29%—Adacore ADA WEB ServerDebian Linux2/26/20256/17/2026
When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).
DeferredHigh (7.5)0.52%—BOA WEB ServerAI12/30/20246/17/2026
Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
DeferredMedium (5.3)0.45%—Goahead WEB ServerAI10/17/20246/17/2026
CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when compiled with the ME_GOAHEAD_JAVASCRIPT flag. This vulnerability allows a remote attacker with the privileges to modify JavaScript template (JST) files to trigger a crash and cause a Denial of…
DeferredMedium (5.9)0.48%—Goahead WEB ServerAI10/17/20246/17/2026
Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAHEAD_REPLACE_MALLOC flag. Without a memory notifier for allocation failures, remote attackers can exploit these vulnerabilities by sending malicious requests, leading to a crash…
DeferredHigh (8.7)13%—Spidercontrol Scada WEB ServerAI9/10/20246/17/2026
SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.
DeferredHigh (7.4)0.37%—Adacore ADA WEB ServerAI8/13/20246/17/2026
An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish connections to external services is done without proper hostname validation. This is exploitable by man-in-the-middle attackers.
DeferredMedium (6.9)0.22%—Campbell Scientific CSI WEB ServerAI5/28/20246/17/2026
The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if an attacker were to gain access to the…
DeferredMedium (5.3)0.49%—Campbell Scientific CSI WEB ServerAI5/28/20246/17/2026
The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression can lead to a path traversal vulnerability. This command combined with a specially crafted expression allows anonymous, unauthenticated access (allowed by…
DeferredMedium (5.8)0.37%—Static-web-server Static WEB ServerAI5/1/20246/17/2026
Static Web Server (SWS) is a tiny and fast production-ready web server suitable to serve static web files or assets. In affected versions if directory listings are enabled for a directory that an untrusted user has upload privileges for, a malicious file name like `<img src=x onerror=alert(1)>.txt` will allow…
DeferredMedium (5.4)0.31%—Hyperion WEB ServerAI4/25/20246/17/2026
Cross-Site Scripting (XSS) vulnerability in Hyperion Web Server affecting version 2.0.15. This vulnerability could allow an attacker to execute malicious Javascript code on the client by injecting that code into the URL.
ModifiedMedium (5.3)0.50%—Cellinx NVT WEB Server2/8/20246/17/2026
An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.
ModifiedMedium (5.4)0.50%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Stored Cross-Site Scripting in Easy Address Book Web Server 1.6 version, through the users_admin.ghp file that affects multiple parameters such as (firstname, homephone, lastname, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate, workzip). This vulnerability allows a remote attacker to…
ModifiedMedium (6.1)0.42%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Vulnerability in Easy Address Book Web Server 1.6 version, affecting the parameters (firstname, homephone, lastname, middlename, workaddress, workcity, workcountry, workphone, workstate and workzip) of the /addrbook.ghp file, allowing an attacker to inject a JavaScript payload specially designed to run when the…
ModifiedCritical (9.8)0.98%—Easy Address Book WEB Server Project Easy Address Book WEB Server10/4/20236/17/2026
Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the remote machine.
ModifiedHigh (7.5)1.2%—Lite-web-server Project Lite-web-server2/25/20236/17/2026
All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
ModifiedHigh (7.5)2.4%—Cellinx NVT WEB Server2/22/20236/17/2026
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFileContent.cgi.
ModifiedHigh (7.5)1.0%—Codesys Development SystemCodesys Edge GatewayCodesys GatewayCodesys HMI SL+66/24/20226/17/2026
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
ModifiedMedium (6.1)3.2%—Zerof WEB Server2/18/20226/17/2026
ZEROF Web Server 2.0 allows /admin.back XSS.
ModifiedCritical (9.8)8.3%—Zerof WEB Server2/18/20226/17/2026
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
ModifiedHigh (7.5)81%—Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4212/14/20216/17/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModifiedMedium (6.1)3.4%—Tiny Java WEB Server Project Tiny Java WEB Server8/9/20216/17/2026
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page