Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.9% | — | Desiderata Software Blazix WEB Server | 29/3/2006 | 16/6/2026 | Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL. | |
| Modificada | Media (5) | 2.1% | — | Pablo Software Solutions Baby ASP WEB ServerPablo Software Solutions Quick AND Easy WEB Server | 25/3/2006 | 16/6/2026 | The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL. | |
| Modificada | Alta (7.8) | 6.8% | 💥 Exploit | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request. | |
| Modificada | Media (6.5) | 2.8% | 💥 Exploit | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder. | |
| Modificada | Media (4.3) | 1.3% | — | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file. | |
| Modificada | Media (5) | 1.4% | — | Solido Systems Ravenous WEB Server | 10/3/2006 | 16/6/2026 | Unspecified vulnerability in Ravenous Web Server before 0.7.1 allows remote attackers to access arbitrary rvplg files, with unknown impact. | |
| Modificada | Media (5) | 1.6% | — | Networkactiv WEB Server | 6/3/2006 | 16/6/2026 | NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Litespeed Technologies Litespeed WEB Server | 20/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Hasbani WEB Server | 3/11/2005 | 16/6/2026 | Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Networkactiv WEB Server | 4/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string. | |
| Modificada | Media (4.3) | 1.4% | — | SUN ONE WEB Server | 5/7/2005 | 16/6/2026 | Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the… | |
| Modificada | Media (5) | 0.99% | — | SUN Java System WEB Server | 7/6/2005 | 16/6/2026 | Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files. | |
| Modificada | Media (5) | 1.9% | — | Jeuce Personal WEB Server | 18/5/2005 | 16/6/2026 | Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow. | |
| Modificada | Alta (7.5) | 1.7% | — | Fastream Netfile FTP WEB Server | 18/5/2005 | 16/6/2026 | The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service. | |
| Modificada | Media (5) | 1.9% | — | Jeuce Personal WEB ServerAI | 18/5/2005 | 16/6/2026 | Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (5) | 1.9% | — | Jeuce Personal WEB Server | 18/5/2005 | 16/6/2026 | Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://". | |
| Modificada | Media (5) | 1.6% | — | Emotion Mediapartner WEB Server | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (4.3) | 1.2% | — | Emotion Mediapartner WEB Server | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML. | |
| Modificada | Media (5) | 1.4% | — | Emotion Mediapartner WEB Server | 2/5/2005 | 16/6/2026 | eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file. | |
| Modificada | Media (5) | 1.8% | — | SUN Java System WEB Server | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang). | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Pmsoftware Simple WEB Server | 2/5/2005 | 16/6/2026 | Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Media (4.3) | 0.94% | — | Minihttpserver.net Forum WEB Server | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Pegasi WEB Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Pegasi WEB Server | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash). |