Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.9%—Desiderata Software Blazix WEB Server29/3/200616/6/2026
Blazix Web Server before 1.2.6, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot), (2) space, and (3) slash characters in the extension of a URL.
ModificadaMedia (5)2.1%—Pablo Software Solutions Baby ASP WEB ServerPablo Software Solutions Quick AND Easy WEB Server25/3/200616/6/2026
The (a) Quick 'n Easy Web Server before 3.1.1 and (b) Baby ASP Web Server 2.7.2 allows remote attackers to obtain the source code of ASP files via (1) . (dot) and (2) space characters in the extension of a URL.
ModificadaAlta (7.8)6.8%💥 ExploitEFS Software EFS WEB Server12/3/200616/6/2026
Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.
ModificadaMedia (6.5)2.8%💥 ExploitEFS Software EFS WEB Server12/3/200616/6/2026
Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
ModificadaMedia (4.3)1.3%—EFS Software EFS WEB Server12/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file.
ModificadaMedia (5)1.4%—Solido Systems Ravenous WEB Server10/3/200616/6/2026
Unspecified vulnerability in Ravenous Web Server before 0.7.1 allows remote attackers to access arbitrary rvplg files, with unknown impact.
ModificadaMedia (5)1.6%—Networkactiv WEB Server6/3/200616/6/2026
NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward slash) after the file extension.
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (4.3)1.9%💥 ExploitLitespeed Technologies Litespeed WEB Server20/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
ModificadaMedia (5)8.3%💥 ExploitHasbani WEB Server3/11/200516/6/2026
Hasbani Web Server (WindWeb) 2.0 allows remote attackers to cause a denial of service (infinite loop) via HTTP crafted GET requests.
ModificadaMedia (4.3)2.0%💥 ExploitNetworkactiv WEB Server4/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.
ModificadaMedia (4.3)1.4%—SUN ONE WEB Server5/7/200516/6/2026
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes SunONE to incorrectly handle and forward the body of the…
ModificadaMedia (5)0.99%—SUN Java System WEB Server7/6/200516/6/2026
Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.
ModificadaMedia (5)1.9%—Jeuce Personal WEB Server18/5/200516/6/2026
Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.
ModificadaAlta (7.5)1.7%—Fastream Netfile FTP WEB Server18/5/200516/6/2026
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.
ModificadaMedia (5)1.9%—Jeuce Personal WEB ServerAI18/5/200516/6/2026
Directory traversal vulnerability in Jeuce Personal Web Server 2.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (5)1.9%—Jeuce Personal WEB Server18/5/200516/6/2026
Jeuce Personal Web Server 2.13 allows remote attackers to cause a denial of service (server crash) via a GET request beginning with "://".
ModificadaMedia (5)1.6%—Emotion Mediapartner WEB Server2/5/200516/6/2026
Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (4.3)1.2%—Emotion Mediapartner WEB Server2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing .. sequences and HTML, which results in a directory browsing page that does not properly filter the HTML.
ModificadaMedia (5)1.4%—Emotion Mediapartner WEB Server2/5/200516/6/2026
eMotion MediaPartner Web Server 5.0 and 5.1 allows remote attackers to obtain sensitive information via an HTTP request for a .bhtml file that contains a (1) . (dot) or (2) + (plus sign) at the end, which returns the source code for that file.
ModificadaMedia (5)1.8%—SUN Java System WEB Server2/5/200516/6/2026
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
ModificadaAlta (7.5)9.7%💥 ExploitPmsoftware Simple WEB Server2/5/200516/6/2026
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaMedia (4.3)0.94%—Minihttpserver.net Forum WEB Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModificadaMedia (5)3.8%💥 ExploitPegasi WEB Server31/12/200416/6/2026
Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.
ModificadaMedia (4.3)2.2%💥 ExploitPegasi WEB Server31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the URI, directly after the initial '/' (slash).