CVE Browser

More filters (active)

Page 1 (more results available)

Vendor: Embedthis Remove filter Clear all
CVE-2023-53155 HIGH

goform/formTest in EmbedThis GoAhead 2.5 allows HTML injection via the name parameter.

CVSS 7.2 EPSS 0.52% Jul 25, 2025
CVE-2024-3187 MEDIUM

This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6.0.0. These are caused by JST values not…

CVSS 5.9 EPSS 0.50% Oct 17, 2024
CVE-2024-3186 MEDIUM

CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when compiled with the ME_GOAHEAD_JAVASCRIPT…

CVSS 5.3 EPSS 0.45% Oct 17, 2024
CVE-2024-3184 MEDIUM

Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAHEAD_REPLACE_MALLOC…

CVSS 5.9 EPSS 0.48% Oct 17, 2024
CVE-2021-41615 CRITICAL

websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded onceuponatimeinparadise value, which d…

CVSS 9.8 EPSS 1.42% Aug 8, 2022
CVE-2021-33254 HIGH

An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramte…

CVSS 7.5 EPSS 1.52% Jun 1, 2022
CVE-2021-43298 CRITICAL

The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and has no rate-limiting. This means that a…

CVSS 9.8 EPSS 2.26% Jan 25, 2022
CVE-2021-42342 CRITICAL

An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed…

CVSS 9.8 EPSS 59.46% Oct 14, 2021
CVE-2020-15688 HIGH

The HTTP Digest Authentication in the GoAhead web server before 5.1.2 does not completely protect against replay attacks. This allows an unauthenticated remote…

CVSS 8.8 EPSS 4.04% Jul 23, 2020
CVE-2020-15689 HIGH

Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may resul…

CVSS 7.5 EPSS 1.33% Jul 13, 2020
CVE-2019-5096 CRITICAL

An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in version…

CVSS 9.8 EPSS 66.98% Dec 3, 2019
CVE-2019-5097 HIGH

A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.…

CVSS 7.5 EPSS 45.06% Dec 3, 2019
CVE-2019-19240 MEDIUM

Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect uses a static host buffer that has a limi…

CVSS 5.3 EPSS 1.54% Nov 22, 2019
CVE-2019-16645 HIGH

An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtaine…

CVSS 8.6 EPSS 8.18% Sep 20, 2019
CVE-2019-12822 HIGH

In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and…

CVSS 7.5 EPSS 8.85% Jun 14, 2019
CVE-2018-15505 HIGH

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause…

CVSS 7.5 EPSS 2.23% Aug 18, 2018
CVE-2018-15504 HIGH

An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which r…

CVSS 7.5 EPSS 2.77% Aug 18, 2018
CVE-2018-8715 HIGH

The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP req…

CVSS 8.1 EPSS 22.79% Mar 14, 2018
CVE-2017-1000471 CRITICAL

EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.

CVSS 9.8 EPSS 8.61% Jan 3, 2018
CVE-2017-1000470 HIGH

EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.

CVSS 7.5 EPSS 7.86% Jan 3, 2018
CVE-2017-17562 KEV HIGH

Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the env…

CVSS 8.1 EPSS 96.26% Dec 12, 2017
CVE-2017-14149 HIGH

GoAhead 3.4.0 through 3.6.5 has a NULL Pointer Dereference in the websDecodeUrl function in http.c, leading to a crash for a "POST / HTTP/1.1" request.

CVSS 7.5 EPSS 5.79% Sep 5, 2017
CVE-2017-5675 HIGH

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera…

CVSS 8.8 EPSS 1.71% Mar 13, 2017
CVE-2017-5674 CRITICAL

A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malforme…

CVSS 9.8 EPSS 21.57% Mar 13, 2017
CVE-2014-9707 HIGH

EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traver…

CVSS 7.5 EPSS 28.24% Mar 31, 2015

Showing 1 to 25 CVEs · page 1 (more available)