Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | — | HP Smart Profile Server Data Analytics Layer | 18/10/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 9.2% | — | Rejetto Http File Server | 10/10/2014 | 17/6/2026 | The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Rejetto Http File Server | 7/10/2014 | 17/6/2026 | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action. | |
| Modificada | Alta (9) | 7.3% | — | Solarwinds Serv-u File Server | 14/12/2011 | 16/6/2026 | Directory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list and create arbitrary directories, via a "..:/" (dot dot colon forward slash) in the (1) list, (2) put, or (3) get commands. | |
| Modificada | Media (4) | 2.9% | — | Solarwinds Serv-u File Server | 27/4/2010 | 16/6/2026 | Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (10) | 83% | — | Solarwinds Serv-u File Server | 20/11/2009 | 16/6/2026 | Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. | |
| Modificada | Media (5) | 4.0% | — | Solarwinds Serv-u File Server | 9/10/2009 | 16/6/2026 | Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command. | |
| Modificada | Alta (7.8) | 11% | — | Solarwinds Serv-u File Server | 20/3/2009 | 16/6/2026 | Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request. | |
| Modificada | Media (4) | 7.0% | — | Solarwinds Serv-u File Server | 19/3/2009 | 16/6/2026 | The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument. | |
| Modificada | Alta (9) | 11% | — | Solarwinds Serv-u File Server | 9/10/2008 | 16/6/2026 | Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command. | |
| Modificada | Media (4) | 10% | — | Solarwinds Serv-u File Server | 9/10/2008 | 16/6/2026 | Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1". | |
| Modificada | Media (4) | 2.1% | — | Solarwinds Serv-u File Server | 20/8/2008 | 16/6/2026 | Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging. | |
| Modificada | Media (5) | 1.8% | — | Group Logic Extremez-ip File ServerGroup Logic Extremez-ip Print Server | 13/2/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a "..\" (dot dot backslash) sequence in the filename. | |
| Modificada | Media (5) | 7.7% | — | Extremez Print ServerExtremez-ip File Server | 13/2/2008 | 16/6/2026 | ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol… | |
| Modificada | Media (5) | 1.7% | — | Group Logic Extremez-ip File ServerGroup Logic Extremez-ip Print Server | 13/2/2008 | 16/6/2026 | ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548. | |
| Modificada | Media (6.4) | 1.7% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authentication. | |
| Modificada | Media (5) | 1.6% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request. | |
| Modificada | Media (5) | 1.8% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication instead of a username and password, as demonstrated by placing this id element in the userinfo subcomponent of a URL. | |
| Modificada | Alta (10) | 3.1% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesting the / URI; and (3) append arbitrary data to a file via a ..… | |
| Modificada | Media (5) | 3.6% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name. | |
| Modificada | Media (4.3) | 1.3% | — | HFS Http File Server | 29/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a URL. | |
| Modificada | Media (4) | 1.4% | — | Xythos Digital LockerXythos Enterprise Document ManagerXythos Webfile Server | 27/6/2007 | 16/6/2026 | Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution. | |
| Modificada | Alta (9.3) | 36% | — | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Media (5) | 2.4% | — | Solarwinds Serv-u File Server | 2/11/2005 | 16/6/2026 | Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and… | |
| Modificada | Alta (7.5) | 15% | — | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. |