Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Aprelium Technologies Abyss WEB Server31/12/200316/6/2026
CRLF injection vulnerability in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to inject arbitrary HTTP headers and possibly conduct HTTP Response Splitting attacks via CRLF sequences in the Location header.
ModificadaMedia (5)1.3%—EFS Software EFS WEB ServerAI31/12/200316/6/2026
Easy File Sharing (EFS) Web Server 1.2 allows remote authenticated users to cause a denial of service via (1) an "empty symbol" in the Title field or (2) certain data in the Your Message field, possibly a long argument.
ModificadaAlta (7.5)12%—Aprelium Technologies Abyss WEB Server31/12/200316/6/2026
Heap-based buffer overflow in Aprelium Abyss Web Server 1.1.2 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaMedia (5)1.7%—Plug AND Play WEB Server Proxy31/10/200316/6/2026
Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080.
ModificadaMedia (5)1.6%—Ashley Brown Iweb Server7/8/200316/6/2026
Directory traversal vulnerability in iWeb Server 2 allows remote attackers to read arbitrary files via an HTTP request containing URL-encoded .. sequences ("%5c%2e%2e"), a different vulnerability than CVE-2003-0474.
ModificadaMedia (5)1.6%—Ashley Brown Iweb Server7/8/200316/6/2026
Directory traversal vulnerability in iWeb Server allows remote attackers to read arbitrary files via an HTTP request containing .. sequences, a different vulnerability than CVE-2003-0475.
ModificadaMedia (6.4)7.4%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
ModificadaAlta (7.5)3.5%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP request, which may trigger a buffer overflow.
ModificadaMedia (6.4)2.2%—Snowblind.net Snowblind WEB Server16/6/200316/6/2026
Directory traversal vulnerability in Snowblind Web Server 1.0 allows remote attackers to list arbitrary directory contents via a ... (triple dot) in an HTTP request.
ModificadaMedia (6.4)5.9%💥 ExploitSnowblind.net Snowblind WEB Server16/6/200316/6/2026
Snowblind Web Server 1.0 allows remote attackers to cause a denial of service (crash) via a URL that ends in a "</" sequence.
ModificadaAlta (7.5)8.2%💥 ExploitWsmp3 DaemonWsmp3 WEB Server22/5/200316/6/2026
Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.
ModificadaMedia (5)3.0%💥 ExploitWsmp3 DaemonWsmp3 WEB Server21/5/200316/6/2026
Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allows remote attackers to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.
ModificadaAlta (7.5)7.7%—IBM Lotus Domino WEB ServerIBM Lotus Notes Client2/4/200316/6/2026
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
ModificadaAlta (10)15%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is…
ModificadaMedia (5)3.0%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.
ModificadaMedia (5)2.5%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
ModificadaBaja (2.1)0.35%—MDG Computer Services WEB Server 4D2/4/200316/6/2026
Web Server 4D (WS4D) 3.6 stores passwords in plaintext in the Ws4d.4DD file, which allows attackers to gain privileges.
ModificadaMedia (5)2.7%💥 ExploitKEY Focus KF WEB Server31/12/200216/6/2026
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
ModificadaMedia (5)1.6%—SWS Simple WEB Server31/12/200216/6/2026
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist.
ModificadaAlta (7.5)2.6%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
ModificadaAlta (7.5)2.1%—Comscripts WEB Server Creator31/12/200216/6/2026
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal (WSC-WebPortal) 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) l parameter to customize.php or the (2) pg parameter to index.php.
ModificadaMedia (5)3.2%💥 ExploitSWS Simple WEB Server31/12/200216/6/2026
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
ModificadaMedia (5)1.6%—Gamecheats Advanced WEB Server Professional31/12/200216/6/2026
advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.
ModificadaMedia (4.3)1.5%💥 ExploitBlueface Falcon WEB Server31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
ModificadaBaja (1.9)2.8%💥 ExploitZeus Technologies Zeus WEB Server31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remote authenticated users to inject arbitrary web script or HTML via the section parameter to index.fcgi.