Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.73% | — | Chendotjs Lotos Webserver | 5/1/2024 | 17/6/2026 | Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled. | |
| Modificada | Crítica (9.8) | 1.8% | — | Easyphp Webserver | 27/9/2023 | 17/6/2026 | An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Spidercontrol Scadawebserver | 2/8/2023 | 17/6/2026 | SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a… | |
| Modificada | Crítica (9.8) | 0.69% | — | Picturethiswebserver Project Picturethiswebserver | 16/1/2023 | 17/6/2026 | A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects the function router.post of the file routes/user.js. The manipulation of the argument username/password leads to sql injection. The patch is named 68b9dc346e88b494df00d88c7d058e96820e1479. It is recommended to apply a… | |
| Modificada | Alta (7.5) | 1.0% | — | Mcwebserver Minecraft MOD FOR Fabric AND Quilt Project Mcwebserver Minecraft MOD FOR Fabric AND QuiltMcwebserver Minecraft MOD FOR Forge Project Mcwebserver Minecraft MOD FOR Forge | 21/9/2022 | 17/6/2026 | McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebserver Minecraft Mod for Fabric and Quilt up to and including 0.1.2.1 and McWebserver Minecraft Mod for Forge up to and including 0.1.1 allows all files, accessible by the program, to be read by anyone… | |
| Modificada | Media (5.3) | 0.84% | — | Aggsoft Webserver | 24/5/2022 | 17/6/2026 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system. | |
| Modificada | Media (6.1) | 0.79% | — | Aggsoft Webserver | 24/5/2022 | 17/6/2026 | The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.1% | — | Ipmatcher Project IpmatcherWatsonwebserver Project Watsonwebserver | 16/5/2022 | 17/6/2026 | An Input Validation Vulnerability exists in Joel Christner .NET C# packages WatsonWebserver, IpMatcher 1.0.4.1 and below (IpMatcher) and 4.1.3 and below (WatsonWebserver) due to insufficient validation of input IP addresses and netmasks against the internal Matcher list of IP addresses and subnets. | |
| Modificada | Crítica (9.8) | 1.9% | — | Honeywell Notifier Webserver | 7/4/2020 | 17/6/2026 | Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem. | |
| Modificada | Crítica (9.1) | 1.3% | — | Honeywell Notifier Webserver | 24/3/2020 | 17/6/2026 | In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser. | |
| Modificada | Alta (7.5) | 6.6% | — | Dart Powertcp Webserver FOR Activex | 23/1/2020 | 16/6/2026 | NULL Pointer Dereference in PowerTCP WebServer for ActiveX 1.9.2 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 2.0% | — | Gcdwebserver Project Gcdwebserver | 10/8/2019 | 17/6/2026 | An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By leveraging this vulnerability, an adversary can make an inaccessible file be available (the credential of the app, for instance). | |
| Modificada | Alta (8.1) | 1.5% | — | Hiawatha-webserver Hiawatha | 16/2/2019 | 17/6/2026 | In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled. | |
| Modificada | Media (6.1) | 0.85% | — | Spidercontrol Scada Webserver | 4/12/2018 | 17/6/2026 | Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to the victim's browser. | |
| Modificada | Crítica (10) | 2.5% | — | Spidercontrol Ininet Webserver | 5/10/2017 | 17/6/2026 | An Improper Authentication issue was discovered in iniNet Solutions iniNet Webserver, all versions prior to V2.02.0100. The webserver does not properly authenticate users, which may allow a malicious attacker to access sensitive information such as HMI pages or modify PLC variables. | |
| Modificada | Alta (7.8) | 0.39% | — | Spidercontrol Scada Webserver | 5/10/2017 | 17/6/2026 | An Improper Privilege Management issue was discovered in SpiderControl SCADA Web Server Version 2.02.0007 and prior. Authenticated, non-administrative local users are able to alter service executables with escalated privileges, which could allow an attacker to execute arbitrary code under the context of the current… | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Miele Professional Pst10 Webserver | 24/3/2017 | 17/6/2026 | An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent… | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 27/12/2011 | 16/6/2026 | GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Monoxide0184 Oxide Webserver | 8/12/2011 | 16/6/2026 | Directory traversal vulnerability in Oxide WebServer allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Goahead Webserver | 3/11/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or… | |
| Modificada | Alta (10) | 6.6% | 💥 Exploit | Timo Gaik Webby Webserver | 27/5/2010 | 16/6/2026 | Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385. | |
| Modificada | Media (5) | 1.6% | — | Goahead WebserverGoahead Software Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function. | |
| Modificada | Alta (7.5) | 1.2% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c. | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server. |