Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Apache Http Server | 18/10/2001 | 16/6/2026 | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. | |
| Modificada | Media (5) | 57% | 💥 Exploit | Apache Http Server | 1/10/2001 | 16/6/2026 | Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string. | |
| Modificada | Media (5) | 4.3% | — | Apache Http Server | 31/8/2001 | 16/6/2026 | Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail. | |
| Modificada | Alta (7.2) | 0.58% | — | IBM Http Server SSL Module Common | 31/8/2001 | 16/6/2026 | ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class. | |
| Modificada | Media (5) | 1.6% | — | MAX Feoktistov Small Http ServerVwebserver | 29/6/2001 | 16/6/2026 | SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests. | |
| Modificada | Media (5) | 1.6% | — | MAX Feoktistov Small Http Server | 27/6/2001 | 16/6/2026 | Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux. | |
| Modificada | Media (5) | 12% | — | Apache Http Server | 12/5/2001 | 16/6/2026 | Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer. | |
| Modificada | Alta (10) | 3.3% | — | A1webserver Http Server | 3/5/2001 | 16/6/2026 | Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Bajie Java Http Server | 3/5/2001 | 16/6/2026 | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Bajie Java Http Server | 3/5/2001 | 16/6/2026 | UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | A1webserver Http Server | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | IBM Http ServerIBM Websphere Application Server | 13/3/2001 | 16/6/2026 | Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. | |
| Modificada | Media (5) | 75% | 💥 Exploit | Apache Http ServerDebian Linux | 12/3/2001 | 16/6/2026 | The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex. | |
| Modificada | Baja (3.3) | 2.3% | — | Apache Http ServerDebian Linux | 12/3/2001 | 16/6/2026 | htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Media (5) | 9.6% | 💥 Exploit | Apache Http Server | 16/2/2001 | 16/6/2026 | PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences. | |
| Modificada | Media (5) | 1.3% | — | MAX Feoktistov Small Http Server | 9/1/2001 | 16/6/2026 | Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | MAX Feoktistov Small Http Server | 9/1/2001 | 16/6/2026 | Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed. | |
| Modificada | Alta (7.5) | 1.9% | — | IBM Http Server | 9/1/2001 | 16/6/2026 | IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request. | |
| Modificada | Media (5) | 1.2% | — | MAX Feoktistov Small Http Server | 9/1/2001 | 16/6/2026 | Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file. | |
| Modificada | Media (5) | 36% | — | Apache Http Server | 19/12/2000 | 23/9/2026 | mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression. | |
| Modificada | Media (5) | 1.3% | — | Fastream FUR Http Server | 14/11/2000 | 16/6/2026 | Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request. | |
| Modificada | Media (5) | 51% | 💥 Exploit | Apache Http ServerSuse Linux | 14/11/2000 | 16/6/2026 | The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method. | |
| Modificada | Media (5) | 45% | — | Apache Http ServerSuse Linux | 14/11/2000 | 16/6/2026 | The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/. | |
| Modificada | Media (5) | 1.9% | — | Bajie Java Http Server | 20/10/2000 | 16/6/2026 | Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. | |
| Modificada | Media (5) | 1.5% | — | Bajie Java Http Server | 20/10/2000 | 16/6/2026 | The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. |