Vulnerabilities

Summary — last 7 days

New vulnerabilities2,737▼ 486 vs. last week
Critical / high1,302▼ 188 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)227▼ 275 vs. last week
–

16 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.7)0.52%—EspasynchttpserverAI9/17/20269/24/2026
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMultipartPostByte processes the boundary. A remote request containing an exactly…
DeferredHigh (8.7)0.43%—EspasynchttpserverAI6/27/20256/17/2026
ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. In versions up to and including 3.7.8, a CRLF (Carriage Return Line Feed) injection vulnerability exists in the construction and output of HTTP headers within `AsyncWebHeader.cpp`. Unsanitized input allows…
ModifiedHigh (7.5)0.88%—Httpserver Project Httpserver12/27/20226/17/2026
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The…
ModifiedMedium (5.3)1.6%—Statichttpserver Project Statichttpserver9/3/20196/17/2026
A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.
ModifiedMedium (5.3)1.3%—Simplehttpserver Project Simplehttpserver12/4/20186/17/2026
A Path Traversal in simplehttpserver versions <=0.2.1 allows to list any file in another folder of web root.
ModifiedHigh (7.5)2.0%—Simplehttpserver Project Simplehttpserver8/31/20186/17/2026
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server.
ModifiedMedium (6.1)4.0%💥 ExploitCybrotech Cybrohttpserver8/29/20186/17/2026
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
ModifiedMedium (5.3)39%💥 ExploitCybrotech Cybrohttpserver8/29/20186/17/2026
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
ModifiedMedium (5.4)0.64%—Simplehttpserver Project Simplehttpserver6/7/20186/17/2026
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModifiedHigh (7.5)2.8%—HP CompaqhttpserverHP System Management Homepage4/13/20066/16/2026
HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL.
ModifiedMedium (4.3)0.97%—Compaqhttpserver9/20/20056/16/2026
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
ModifiedMedium (4.3)0.94%—Minihttpserver.net Forum WEB Server12/31/20046/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModifiedMedium (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI12/31/20046/16/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModifiedMedium (5)1.5%—Minihttpserver.net WEB Forums Server12/31/20046/16/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModifiedMedium (5)1.4%—Geovision Geohttpserver12/31/20046/16/2026
GeoHttpServer, when configured to authenticate users, allows remote attackers to bypass authentication and access unauthorized files via a URL that contains %0a%0a (encoded newlines).
ModifiedMedium (5)1.9%—Geovision Geohttpserver12/31/20046/16/2026
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.