CVE-2026-29046
- EPSS 0.24%
- Veröffentlicht 06.03.2026 02:54:11
- Zuletzt bearbeitet 16.03.2026 15:00:12
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header values and later maps them into CGI environment variables (HTTP_*). The parser did not strictly reject dangerous control characte...
CVE-2026-28497
- EPSS 0.17%
- Veröffentlicht 06.03.2026 02:51:59
- Zuletzt bearbeitet 16.03.2026 15:37:17
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerability in the string-to-integer conversion routine (_Val) allows an unauthenticated remote attacker to bypass Content-Length restrict...
CVE-2026-27633
- EPSS 0.14%
- Veröffentlicht 25.02.2026 23:07:35
- Zuletzt bearbeitet 28.02.2026 01:00:49
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticated remote attackers can send an HTTP POST request to the server with an...
CVE-2026-27630
- EPSS 0.14%
- Veröffentlicht 25.02.2026 23:05:16
- Zuletzt bearbeitet 28.02.2026 01:01:22
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server spawns a new OS thread for every incoming connection without enforcing...
CVE-2026-27613
- EPSS 0.15%
- Veröffentlicht 25.02.2026 22:58:16
- Zuletzt bearbeitet 04.03.2026 03:21:58
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unauthenticated remote attackers to bypass the web server's CGI parameter security controls. Depending on the server configuration and...
CVE-2026-22781
- EPSS 0.58%
- Veröffentlicht 12.01.2026 18:23:00
- Zuletzt bearbeitet 16.01.2026 18:44:23
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the ...
CVE-2024-5193
- EPSS 0.39%
- Veröffentlicht 22.05.2024 11:15:53
- Zuletzt bearbeitet 05.01.2026 19:15:55
A security vulnerability has been detected in Ritlabs TinyWeb Server 1.94. This vulnerability affects unknown code of the component Request Handler. The manipulation with the input %0D%0A leads to crlf injection. It is possible to initiate the attack...
CVE-2024-34199
- EPSS 1.32%
- Veröffentlicht 14.05.2024 15:38:32
- Zuletzt bearbeitet 05.01.2026 16:15:41
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.