Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.3%—Iplanet WEB Server23/7/200216/6/2026
Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter.
ModificadaMedia (5)3.5%💥 ExploitGoahead Software Goahead WebserverOrange Software Orange WEB ServerMontavista Software Hard HAT Linux23/7/200216/6/2026
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.
ModificadaMedia (5)9.8%💥 ExploitAprelium Technologies Abyss WEB Server3/7/200216/6/2026
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request.
ModificadaAlta (7.2)0.79%💥 ExploitAprelium Technologies Abyss WEB Server3/7/200216/6/2026
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.
ModificadaMedia (5)2.1%—Essentia WEB Server25/6/200216/6/2026
Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
ModificadaAlta (7.5)9.8%💥 ExploitEssentia WEB Server25/6/200216/6/2026
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.
ModificadaMedia (5)2.4%—Blueface Falcon WEB Server31/5/200216/6/2026
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.
ModificadaMedia (5)21%💥 ExploitCyberstop WEB Server16/5/200216/6/2026
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
ModificadaMedia (5)7.3%💥 PoCCyberstop WEB Server16/5/200216/6/2026
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.
ModificadaAlta (7.5)3.3%—MDG Computer Services WEB Server 4D Ecommerce25/3/200216/6/2026
MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
ModificadaMedia (5)2.0%—MDG Computer Services WEB Server 4D Ecommerce25/3/200216/6/2026
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
ModificadaMedia (5)3.4%💥 ExploitNovell WEB Server15/1/200228/9/2026
Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.
ModificadaAlta (7.5)2.4%—Lotus Domino WEB Server6/12/200116/6/2026
Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.
ModificadaAlta (10)15%💥 ExploitIplanet WEB Server18/10/200116/6/2026
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.
ModificadaAlta (7.5)2.6%—Iplanet WEB Server18/10/200116/6/2026
Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long method name in an HTTP request.
ModificadaMedia (5)2.2%—HP VirtualvaultSUN Iplanet WEB Server22/8/200116/6/2026
Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.
ModificadaMedia (5)11%💥 ExploitT. Hauck Jana WEB Server14/8/200116/6/2026
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).
ModificadaMedia (5)7.3%💥 ExploitT. Hauck Jana WEB Server14/8/200116/6/2026
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).
ModificadaMedia (5)5.2%💥 ExploitOrange Software Orange WEB Server6/8/200116/6/2026
Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.
ModificadaAlta (10)1.5%—Iplanet WEB Server2/7/200116/6/2026
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.
ModificadaMedia (5)3.1%—Iplanet WEB Server2/7/200116/6/2026
iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server.
ModificadaMedia (5)2.3%—Netcruiser Software Netcruiser WEB Server27/6/200116/6/2026
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.
ModificadaMedia (5)3.6%💥 ExploitSpencer Christensen Perl WEB Server27/6/200116/6/2026
Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (5)0.97%—Iplanet WEB Server11/6/200116/6/2026
Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.
ModificadaMedia (5)2.4%—Free Java WEB Server3/5/200116/6/2026
Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.