Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

505 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.7%💥 ExploitPerception Liteserve31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.
ModificadaMedia (5)6.7%💥 ExploitPerception Liteserve31/12/200216/6/2026
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").
ModificadaMedia (5)1.8%—Sabre Desktop Reservation Software28/10/200216/6/2026
The Sabserv client component in Sabre Desktop Reservation Software 4.2 through 4.4 allows remote attackers to cause a denial of service via malformed input to TCP port 1001.
ModificadaAlta (7.5)3.3%—Analogx Simpleserver Shout4/10/200216/6/2026
Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001.
ModificadaAlta (7.5)6.5%💥 ExploitAnalogx Simpleserver WWW4/10/200216/6/2026
Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.
ModificadaMedia (5)7.1%💥 ExploitMenasoft Sphereserver26/7/200216/6/2026
Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large number of connections to the server without providing login credentials, which prevents other users from being able to log in.
ModificadaAlta (7.5)1.6%—Etype Eserv16/5/200216/6/2026
Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
ModificadaMedia (5)1.6%—Etype Eserv16/5/200216/6/2026
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.
ModificadaMedia (5)8.1%💥 ExploitEtype Eserv25/3/200216/6/2026
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
ModificadaAlta (7.5)3.0%—Caldera Openlinux WorkstationRedhat Linux PowertoolsCaldera Openlinux EserverRedhat Linux+121/12/200116/6/2026
Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands.
ModificadaMedia (5)3.1%—Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenlinuxCaldera Openlinux Edesktop+36/12/200116/6/2026
Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie.
ModificadaAlta (7.5)2.0%—Cmfperception Liteserve18/10/200116/6/2026
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
ModificadaAlta (7.5)2.1%—Caldera Openlinux EdesktopCaldera Openlinux Eserver31/8/200116/6/2026
telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option.
ModificadaCrítica (9.8)1.9%—Lightwavemo Consoleserver 3200 Firmware2/7/200116/6/2026
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
ModificadaMedia (5)3.3%💥 ExploitAnalogx Simpleserver WWW2/7/200116/6/2026
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
ModificadaMedia (5)2.1%—Lightwave Consoleserver2/7/200116/6/2026
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.
ModificadaAlta (10)5.2%—Caldera Openlinux DesktopCaldera Openlinux EdesktopCaldera Openlinux Eserver26/3/200116/6/2026
Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.
ModificadaBaja (1.2)0.34%—Caldera Openlinux DesktopImmunixCaldera Openlinux EdesktopCaldera Openlinux Eserver+312/3/200116/6/2026
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
ModificadaAlta (7.2)1.4%💥 ExploitImmunixConectiva LinuxCaldera OpenlinuxCaldera Openlinux Edesktop+59/1/200116/6/2026
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
ModificadaAlta (10)79%💥 ExploitCaldera Openlinux EbuilderCaldera OpenlinuxCaldera Openlinux EdesktopCaldera Openlinux Eserver+219/12/200023/9/2026
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.5)2.0%—Etype Eserv19/12/200023/9/2026
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.
ModificadaAlta (10)16%💥 ExploitCaldera Openlinux EbuilderImmunixConectiva LinuxSGI Irix+1214/11/200016/6/2026
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
ModificadaMedia (5)7.9%💥 ExploitAnalogx Simpleserver WWW26/7/200016/6/2026
AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.
ModificadaMedia (5)9.9%💥 ExploitCaldera Openlinux DesktopCaldera Openlinux EbuilderCaldera Openlinux EdesktopCaldera Openlinux Eserver+24/7/200016/6/2026
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
ModificadaAlta (7.5)2.6%💥 ExploitAnalogx Simpleserver WWW15/6/200016/6/2026
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.