27 exploited vulnerabilities in Lighttpd
- Vendors
- Totolink, Lighttpd, Alt Linux, Grandstream, Cdata, Suse
- With known exploits
- 27
- Affected Grandstream gac2500 Firmware versions
- ≤ 1.0.3.35
- Affected Lighttpd versions
- < 1.4.35, 1.4.67, 1.4.56, 1.4.57, 1.4.58, 1.4.15, 1.4.31, 1.4.32, 1.4.30, 1.5.0, 1.4.25, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 1.1.9, 1.2.0, 1.2.1, 1.2.2, 1.2.3, 1.2.5, 1.2.6, 1.2.7, 1.2.8, 1.3.0, 1.3.1, 1.3.2, 1.3.3, 1.3.4, 1.3.5, 1.3.6, 1.3.8, 1.3.9, 1.3.10, 1.3.11, 1.3.12, 1.3.13, 1.3.14, 1.3.15, 1.3.16, 1.4.0, 1.4.2, 1.4.3, 1.4.18
- Affected Hanwhasecurity Web Viewer versions
- = 1.0.0.193
Vulnerabilities with exploits
Highest CVSS first — 12 of these already have exploit code on Sploitus
CVE-2026-15701
CVE-2026-7546
CVE-2025-70327
CVE-2019-11072
CVE-2019-10655 6 exploits
Grandstream GXV31XX 'settimezone' Unauthenticated Command ExecutionGrandstream GXV31XX settimezone Unauthenticated Command Execution Exploit
CVE-2020-29058
CVE-2014-2323 2 exploits
Vision2 - Nmap's XML result parse and NVD's CPE correlation to search CVElighttpd 'mod_mysql_vhost.c' SQL注入漏洞
CVE-2025-34125
CVE-2017-16524 6 exploits
Samsung SRN-1670D Web Viewer 1.0.0.193 Arbitrary File Read / UploadWeb Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload Exploit
CVE-2025-67445
CVE-2022-41556 3 exploits
📄 Lighttpd 1.4.66 FastCGI Resource ExhaustionLighttpd 1.4.56 - 1.4.66 Resource Leak Denial of Service PoC
CVE-2022-37797
CVE-2018-19052
CVE-2015-3200 1 exploit
CVE-2022-30780 2 exploits
CVE-2020-24573
CVE-2019-5149
CVE-2014-2324 2 exploits
CVE-2013-4508
CVE-2025-2956
CVE-2025-8759
CVE-2022-22707
CVE-2007-3947 2 exploits
Lighttpd 1.4.15 - Multiple Code Execution Denial of Service Information Disclosure VulnerabilitiesLighttpd 1.4.15 - Multiple Code Execution / Denial of Service / Information Disclosure Vulnerabilities
CVE-2012-5533 6 exploits
CVE-2011-4362 7 exploits
CVE-2010-0295 3 exploits
CVE-2008-1270 1 exploit