Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.2% | — | CurlLibcurlWget | 13/10/2005 | 16/6/2026 | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username. | |
| Modificada | Media (5) | 1.7% | — | GNU Wget | 27/4/2005 | 16/6/2026 | wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences. | |
| Modificada | Media (5) | 12% | — | GNU Wget | 27/4/2005 | 16/6/2026 | wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code. | |
| Modificada | Baja (2.6) | 0.96% | — | GNU Wget | 31/12/2004 | 16/6/2026 | Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded. | |
| Modificada | Media (5) | 4.2% | — | GNU WgetSUN Cobalt RAQ XTR | 18/12/2002 | 16/6/2026 | Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences. | |
| Modificada | Media (5) | 1.5% | — | GNU Wget | 2/1/1999 | 16/6/2026 | wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. |