Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.8%—Radiobird Software WEB Server 4 Everyone31/12/200216/6/2026
Buffer overflow in RadioBird WebServer 4 Everyone 1.28 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request with the Host header set.
ModificadaMedia (5)2.3%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.
ModificadaAlta (7.5)2.7%—SWS Simple WEB Server31/12/200216/6/2026
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.
ModificadaMedia (5)18%—SWS Simple WEB Server31/12/200216/6/2026
Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.
ModificadaAlta (10)3.4%—HP Secure WEB Server FOR Tru6431/12/200216/6/2026
Unspecified vulnerability in Internet Group Management Protocol (IGMP) of HP Tru64 4.0F through 5.1A allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: this might be the same issue as CVE-2002-2185, but there are insufficient details to be certain.
ModificadaMedia (6.8)2.0%—Iplanet WEB Server29/11/200216/6/2026
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
ModificadaMedia (6.8)1.6%—Iplanet WEB Server29/11/200216/6/2026
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with…
ModificadaAlta (7.5)7.1%💥 ExploitPeter Sandvik Simple WEB Server12/11/200216/6/2026
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.
ModificadaMedia (5)3.2%💥 ExploitNorthern Solutions Xeneo WEB Server12/11/200216/6/2026
Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause a denial of service (crash) via a GET request for a "%" URI.
ModificadaMedia (5)1.5%—Aprelium Technologies Abyss WEB Server4/10/200216/6/2026
The Administration console for Abyss Web Server 1.0.3 allows remote attackers to read files without providing login credentials via an HTTP request to a target file that ends in a "+" character.
ModificadaAlta (7.5)2.7%—T. Hauck Jana WEB Server4/10/200216/6/2026
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
ModificadaAlta (7.5)1.8%—Blueface Falcon WEB Server4/10/200216/6/2026
Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).
ModificadaAlta (7.5)5.5%—T. Hauck Jana WEB Server4/10/200216/6/2026
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP GET request with a long major version number, (2) an HTTP GET request to the HTTP proxy on port 3128 with a long major…
ModificadaMedia (5)2.4%—T. Hauck Jana WEB Server4/10/200216/6/2026
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes all available FTP ports.
ModificadaMedia (5)3.9%💥 ExploitNetscape Enterprise ServerSUN Iplanet WEB ServerSUN ONE Application ServerSUN ONE WEB Server4/10/200216/6/2026
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
ModificadaMedia (5)2.3%—T. Hauck Jana WEB Server4/10/200216/6/2026
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
ModificadaMedia (5)2.8%—Aprelium Technologies Abyss WEB Server4/10/200216/6/2026
Abyss Web Server 1.0.3 allows remote attackers to list directory contents via an HTTP GET request that ends in a large number of / (slash) characters.
ModificadaAlta (7.5)1.4%—T. Hauck Jana WEB Server4/10/200216/6/2026
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.
ModificadaMedia (5)8.0%💥 ExploitKEY Focus KF WEB Server4/10/200216/6/2026
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.
ModificadaAlta (7.5)2.3%—KEY Focus KF WEB Server4/10/200216/6/2026
Buffer overflow in KeyFocus (KF) web server 1.0.5 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed HTTP header.
ModificadaAlta (7.5)4.1%—T. Hauck Jana WEB Server4/10/200216/6/2026
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.
ModificadaMedia (5)4.7%💥 ExploitAprelium Technologies Abyss WEB Server4/10/200216/6/2026
Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.
ModificadaAlta (7.5)1.8%—Aprelium Technologies Abyss WEB Server4/10/200216/6/2026
The Administration console for Abyss Web Server 1.0.3 before Patch 2 allows remote attackers to gain privileges and modify server configuration via direct requests to CHL files such as (1) srvstatus.chl, (2) consport.chl, (3) general.chl, (4) srvparam.chl, and (5) advanced.chl.
ModificadaAlta (7.5)67%💥 ExploitSavant WEB Server24/9/200216/6/2026
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)13%—Iplanet WEB Server12/8/200216/6/2026
Buffer overflow in Sun ONE / iPlanet Web Server 4.1 and 6.0 allows remote attackers to execute arbitrary code via an HTTP request using chunked transfer encoding.