Vulnerabilities

Summary — last 7 days

New vulnerabilities3,081▲ 625 vs. last week
Critical / high1,483▲ 317 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)393▲ 186 vs. last week
–

374 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisCritical (9.4)0.40%—Litespeed WEB ServerAI9/30/20269/30/2026
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
DeferredHigh (7.4)0.85%—Tenda Hg10AIBOA WEB ServerAI9/6/20269/11/2026
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly…
DeferredHigh (7.4)0.85%—Tenda Hg10AIBOA WEB ServerAI9/3/20269/3/2026
A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formWlanSetup of the file /boaform/formWlanSetup of the component Boa Web Server. The manipulation of the argument ssid leads to buffer overflow. Remote exploitation of the attack is possible. The exploit is publicly available and might…
DeferredHigh (8.9)1.1%—Tenda Hg10AIBOA WEB ServerAI9/3/20269/3/2026
A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed…
DeferredCritical (9.3)1.1%—Tenda Hg10AIBOA WEB ServerAI8/30/20269/1/2026
A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has…
DeferredMedium (4.3)0.39%—Static-web-server Static WEB ServerAI8/26/20269/9/2026
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated remote attacker to retrieve Prometheus…
DeferredHigh (8.7)0.54%—FDS WEB ServerAI8/20/20269/3/2026
An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be…
DeferredMedium (5.5)0.32%—Ritlabs Tinyweb ServerAI6/15/20267/24/2026
A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32. This impacts an unknown function in the library libeay32.dll.html of the component Header Handler. The manipulation of the argument Authorization leads to stack-based buffer overflow. The attack can be initiated remotely. The…
Awaiting AnalysisHigh (8.8)0.34%—Nordex N149 4.0-4.5 Wind Turbine WEB ServerAI5/17/20266/17/2026
Nordex N149/4.0-4.5 Wind Turbine Web Server 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the login parameter in login.php. Attackers can submit crafted POST requests with SQL injection payloads in the login field…
DeferredHigh (8.2)0.25%—Zervit Portable Http WEB ServerAI4/21/20269/30/2026
Zervit's portable HTTP/web server is vulnerable to remote DoS attacks when a configuration reset request is made. The vulnerability is caused by inadequate validation of user-supplied input. An attacker can exploit this vulnerability by sending malicious requests. If the vulnerability is successfully exploited, the…
AnalyzedHigh (7.5)6.6%⚠ Active exploitationApache TomcatRedhat Jboss WEB ServerRedhat Enterprise LinuxRedhat Enterprise Linux ELS+34/9/20269/21/2026
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Awaiting AnalysisHigh (8.7)0.27%—Hisecos WEB ServerAI4/2/20267/24/2026
HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privilege escalation vulnerability that allows authenticated users with operator or auditor roles to escalate privileges to the administrator role by sending specially crafted packets to the web server. Attackers can exploit this flaw to gain full…
AnalyzedMedium (6.9)0.22%—Networkactiv WEB Server3/30/20266/17/2026
NetworkActiv Web Server 4.0 contains a buffer overflow vulnerability in the username field of the Security options that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by entering a crafted username value exceeding the expected buffer…
AnalyzedHigh (8.6)2.1%—Litespeedtech Litespeed WEB ServerLitespeedtech Openlitespeed3/16/20266/17/2026
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.
DeferredHigh (8.6)0.15%—Easy File Sharing WEB ServerAI3/11/20266/17/2026
Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer…
DeferredHigh (8.7)0.34%—Mongoose WEB ServerAI3/6/20266/17/2026
Mongoose Web Server 6.9 contains a denial of service vulnerability that allows remote attackers to crash the service by establishing multiple socket connections. Attackers can repeatedly create connections to the default port and send malformed data to exhaust server resources and cause service unavailability.
DeferredMedium (5.5)0.54%—Zaher1307 Tiny WEB ServerAI2/22/20266/17/2026
A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b. This affects the function tiny_web_server/tiny.c of the file tiny_web_server/tiny.c of the component URL Handler. This manipulation causes out-of-bounds write. The attack can be initiated remotely. The exploit…
AnalyzedMedium (5.3)0.43%—Static-web-server Static WEB Server2/21/20266/17/2026
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. In versions 2.1.0 through 2.40.1, a timing-based username enumeration vulnerability in Basic Authentication allows attackers to identify valid users by exploiting early responses for invalid usernames, enabling targeted…
DeferredHigh (8.6)1.6%—Litespeed WEB Server EnterpriseAI1/23/20266/17/2026
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash…
DeferredMedium (6.9)1.1%—Brightsign Digital Signage Diagnostic WEB ServerAI12/10/20256/17/2026
BrightSign Digital Signage Diagnostic Web Server 8.2.26 and less contains an unauthenticated server-side request forgery vulnerability in the 'url' GET parameter of the Download Speed Test service. Attackers can specify external domains to bypass firewalls and perform network enumeration by forcing the application to…
AnalyzedMedium (5.5)0.42%—Static-web-server Static WEB Server12/9/20256/17/2026
Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Versions 2.40.0 and below contain symbolic links (symlinks) which can be used to access files or directories outside the intended web root folder. SWS generally does not prevent symlinks from escaping the web server’s…
DeferredHigh (8.7)0.62%—National Instruments System WEB ServerAI12/4/20256/17/2026
There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure. Successful exploitation requires an attacker to send a specially crafted request to the NI System Web Server, allowing the attacker to read arbitrary files. This vulnerability existed in the NI…
DeferredMedium (5.1)0.32%—Desknet WEB ServerAI10/16/20256/17/2026
Reflected cross-site scripting (XSS) vulnerability in desknet's Web Server allows execution of arbitrary JavaScript in a user’s web browser.
DeferredMedium (6.9)0.33%—Lexmark Embedded WEB ServerAI9/9/20256/17/2026
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the embedded web server in various Lexmark devices. This vulnerability can be leveraged by an attacker to force the device to send an arbitrary HTTP request to a third-party server. Successful exploitation of this vulnerability can lead to…
AnalyzedHigh (7.5)0.36%—Adacore ADA WEB Server9/3/20256/17/2026
Adacore Ada Web Server (AWS) before 25.2 is vulnerable to a denial-of-service (DoS) condition due to improper handling of SSL handshakes during connection initialization. When a client initiates an HTTPS connection, the server performs the SSL handshake before assigning the connection to a processing slot. However,…