Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Aprelium Technologies Abyss WEB Server | 31/12/2003 | 16/6/2026 | CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header. | |
| Modificada | Media (5) | 1.3% | — | EFS Software EFS WEB ServerAI | 31/12/2003 | 16/6/2026 | Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument. | |
| Modificada | Alta (7.5) | 12% | — | Aprelium Technologies Abyss WEB Server | 31/12/2003 | 16/6/2026 | Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 1.7% | — | Plug AND Play WEB Server Proxy | 31/10/2003 | 16/6/2026 | Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080. | |
| Modificada | Media (5) | 1.6% | — | Ashley Brown Iweb Server | 7/8/2003 | 16/6/2026 | Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474. | |
| Modificada | Media (5) | 1.6% | — | Ashley Brown Iweb Server | 7/8/2003 | 16/6/2026 | Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475. | |
| Modificada | Media (6.4) | 7.4% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow. | |
| Modificada | Media (6.4) | 2.2% | — | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request. | |
| Modificada | Media (6.4) | 5.9% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence. | |
| Modificada | Alta (7.5) | 8.2% | 💥 Exploit | Wsmp3 DaemonWsmp3 WEB Server | 22/5/2003 | 16/6/2026 | Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Wsmp3 DaemonWsmp3 WEB Server | 21/5/2003 | 16/6/2026 | Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests. | |
| Modificada | Alta (7.5) | 7.7% | — | IBM Lotus Domino WEB ServerIBM Lotus Notes Client | 2/4/2003 | 16/6/2026 | Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control. | |
| Modificada | Alta (10) | 15% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is… | |
| Modificada | Media (5) | 3.0% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form. | |
| Modificada | Media (5) | 2.5% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name. | |
| Modificada | Baja (2.1) | 0.35% | — | MDG Computer Services WEB Server 4D | 2/4/2003 | 16/6/2026 | Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | KEY Focus KF WEB Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences. | |
| Modificada | Media (5) | 1.6% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist. | |
| Modificada | Alta (7.5) | 2.6% | — | Iplanet WEB ServerNetscape Enterprise Server | 31/12/2002 | 16/6/2026 | iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection. | |
| Modificada | Alta (7.5) | 2.1% | — | Comscripts WEB Server Creator | 31/12/2002 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline. | |
| Modificada | Media (5) | 1.6% | — | Gamecheats Advanced WEB Server Professional | 31/12/2002 | 16/6/2026 | advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Blueface Falcon WEB Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages. | |
| Modificada | Baja (1.9) | 2.8% | 💥 Exploit | Zeus Technologies Zeus WEB Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi. |