Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

620 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.5%💥 ExploitBlueface Falcon WEB Server31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages.
ModificadaMedia (4.3)7.3%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
ModificadaMedia (5)1.9%—Blue World Communications Lasso WEB Data Engine31/12/200216/6/2026
Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL.
ModificadaMedia (5)2.5%—Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+84/11/200216/6/2026
Implementaciones de IPSEC, incluyendo FreeS/WAN y KAME no calculan adecuadamente la longitud de los datos de autenticación, lo que permite a atacantes remotos causar una denegación de servicio (kernel panic) mediante paquetes Encapsulating Security Payload (EPS) cortos falsificados, lo que resulta en errores de…
ModificadaMedia (5)3.2%💥 ExploitWorking Resources Inc. Badblue4/10/200216/6/2026
BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.
ModificadaAlta (7.5)2.7%—Working Resources Inc. Badblue4/10/200216/6/2026
BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges.
ModificadaMedia (4.3)4.9%💥 ExploitBluecoat Cacheos4/10/200216/6/2026
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted…
ModificadaMedia (5)3.2%💥 ExploitWorking Resources Inc. Badblue4/10/200216/6/2026
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
ModificadaAlta (7.5)1.8%—Blueface Falcon WEB Server4/10/200216/6/2026
Falcon web server 2.0.0.1021 y anteriores permite a atacantes remotos sortear restricciones de acceso de ficheros protegidos mediante una URL cuya porción de directorio acaba en . (punto).
ModificadaMedia (5)1.6%—Working Resources Inc. Badblue12/8/200216/6/2026
BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end.
ModificadaAlta (7.5)1.6%—Working Resources Inc. Badblue25/6/200216/6/2026
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.
ModificadaMedia (5)38%💥 ExploitWorking Resources Inc. Badblue25/6/200216/6/2026
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.
ModificadaAlta (7.5)4.8%💥 ExploitCodeblue31/5/200216/6/2026
Desbordamiento de búfer en CodeBlue 4 y anteriores, y posíblemente otras versiones, permite a atacantes remotos ejecutar código arbitrario mediante una cadena larga en una respuesta SMTP.
ModificadaMedia (5)2.4%—Blueface Falcon WEB Server31/5/200216/6/2026
El servidor web Falcon 2.0.0.1020 y anteriores permite a atacantes remotos evitar la autenticación y leer ficheros restringidos mediante una barra extra (/) en la URL pedida.
ModificadaMedia (5)2.3%—Working Resources Inc. Badblue22/8/200116/6/2026
BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.
ModificadaMedia (6.4)3.5%💥 ExploitWorking Resources Inc. Badblue3/5/200116/6/2026
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path.
ModificadaAlta (10)11%💥 ExploitWorking Resources Inc. Badblue3/5/200116/6/2026
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
ModificadaAlta (7.5)1.1%—Bluestone Sapphire WEB11/4/200016/6/2026
The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs.
ModificadaMedia (5)1.3%—Blueface Falcon WEB Server26/10/199916/6/2026
Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)1.3%—Blue World Communications Lasso CGI19/8/199716/6/2026
Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.