IT
56.742 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

Search: http

2708 CVE

Search: http
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-22233 HIGH 7.5 vmware spring_framework In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the ap 1.0%
CVE-2020-5931 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.5, 14.1.0-14.1.2.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, Virtual servers with a OneConnect profile may incorrectly handle WebSockets related HTTP response headers, causing TMM to restart. 1.0%
CVE-2020-5871 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.2.3, undisclosed requests can lead to a denial of service (DoS) when sent to BIG-IP HTTP/2 virtual servers. The problem can occur when ciphers, which have been blacklisted by the HTTP/2 RFC, are used on backend servers. This is a data-pla 1.0%
CVE-2020-5859 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file. 1.0%
CVE-2020-5857 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior may lead to a denial of service. 1.0%
CVE-2019-6660 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.1, undisclosed HTTP requests may consume excessive amounts of systems resources which may lead to a denial of service. 1.0%
CVE-2024-23111 MED 6.8 fortinet fortios An improper neutralization of input during web page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS version 7.4.3 and below, 7.2 all versions, 7.0 all versions and FortiProxy version 7.4.2 and below, 7.2 all versions, 7.0 all versions reb 1.0%
CVE-2026-21250 HIGH 7.8 microsoft windows_11_24h2 Untrusted pointer dereference in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2020-3333 MED 5.3 cisco application_policy_infrastructure_controller A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an 1.0%
CVE-2023-1829 HIGH 7.8 linux linux_kernel A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly deactivate filters in case of a perfect hashes while deleting 1.0%
CVE-2007-6190 LOW 3.5 cisco unified_ip_phone The HTTP daemon in the Cisco Unified IP Phone, when the Extension Mobility feature is enabled, allows remote authenticated users of other phones associated with the same CUCM server to eavesdrop on the physical environment via a CiscoIPPhoneExecute message con 1.0%
CVE-2014-3399 MED 5.5 cisco adaptive_security_appliance_software The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cach 1.0%
CVE-2026-27784 HIGH 7.8 f5 nginx_open_source The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only 1.0%
CVE-2021-0202 HIGH 7.5 juniper junos On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPC (Modular Port Concentrator) where Integrated Routing and Bridging (IRB) interface is configured and it is mapped to a VPLS instance or a Bridge-Domain, certain network events at Cust 1.0%
CVE-2026-32952 MED 5.3 microsoft go-ntlmssp go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport 1.0%
CVE-2022-20912 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20911 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20904 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20903 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20902 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20901 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20900 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20899 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20898 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%
CVE-2022-20897 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.0%