Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

337 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)6.2%💥 ExploitMacromedia ColdfusionMacromedia Coldfusion Professional31/12/200316/6/2026
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
ModificadaMedia (5)1.8%—Macromedia ColdfusionMacromedia Coldfusion Professional31/12/200216/6/2026
Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.
ModificadaMedia (5)1.6%—Gamecheats Advanced WEB Server Professional31/12/200216/6/2026
advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence.
ModificadaAlta (7.5)32%—Cgiscript Csnews Professional31/12/200216/6/2026
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
ModificadaAlta (10)13%💥 ExploitCgiscript Cssearch Professional12/8/200216/6/2026
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi.
ModificadaAlta (7.5)7.0%💥 ExploitOreilly Website Professional22/8/200116/6/2026
O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character.
ModificadaMedia (5)2.1%—Ascii NT Winwrapper Professional22/8/200116/6/2026
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.
ModificadaAlta (10)13%💥 ExploitOreilly Website Professional19/7/200016/6/2026
Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter.
ModificadaAlta (10)5.3%—Oreilly Website Professional17/7/200016/6/2026
Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.
ModificadaAlta (10)4.5%💥 ExploitNetscape Professional Services Ftpserver21/6/200016/6/2026
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)2.0%—Oreilly Website Professional13/1/200016/6/2026
WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.
ModificadaBaja (2.1)0.40%—Webtrends Enterprise SuiteWebtrends FOR FirewallsWebtrends LOG AnalyzerWebtrends Professional Suite+129/6/199916/6/2026
WebTrends software stores account names and passwords in a file which does not have restricted access permissions.
Orbitaley — Vulnerabilidades