Vulnerabilities
Summary — last 7 days
New vulnerabilities2,761▲ 86 vs. last week
Critical / high1,460▲ 350 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)91▼ 420 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.7) | 0.43% | — | GNU Libmicrohttpd | 11/10/2025 | 6/17/2026 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. | |
| Analyzed | High (8.7) | 0.43% | — | GNU Libmicrohttpd | 11/10/2025 | 6/17/2026 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition. | |
| Modified | Medium (5.9) | 1.3% | — | GNU Libmicrohttpd | 2/28/2023 | 6/17/2026 | GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data… | |
| Modified | Critical (9.8) | 8.7% | — | GNU LibmicrohttpdRedhat Enterprise LinuxFedoraproject Fedora | 3/25/2021 | 6/17/2026 | A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data confidentiality and integrity as well as… | |
| Modified | Medium (5.1) | 3.3% | — | GNU Libmicrohttpd | 12/13/2013 | 6/17/2026 | Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header. | |
| Modified | Medium (6.4) | 1.8% | — | GNU Libmicrohttpd | 12/13/2013 | 6/17/2026 | The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read. |