Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Blueface Falcon WEB Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Falcon web server 2.0.0.1009 through 2.0.0.1021 allows remote attackers to inject arbitrary web script or HTML via the URI, which is inserted into 301 error messages and executed by 404 error messages. | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI. | |
| Modificada | Media (5) | 1.9% | — | Blue World Communications Lasso WEB Data Engine | 31/12/2002 | 16/6/2026 | Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL. | |
| Modificada | Media (5) | 2.5% | — | Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+8 | 4/11/2002 | 16/6/2026 | Implementaciones de IPSEC, incluyendo FreeS/WAN y KAME no calculan adecuadamente la longitud de los datos de autenticación, lo que permite a atacantes remotos causar una denegación de servicio (kernel panic) mediante paquetes Encapsulating Security Payload (EPS) cortos falsificados, lo que resulta en errores de… | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte. | |
| Modificada | Alta (7.5) | 2.7% | — | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Bluecoat Cacheos | 4/10/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted… | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. | |
| Modificada | Alta (7.5) | 1.8% | — | Blueface Falcon WEB Server | 4/10/2002 | 16/6/2026 | Falcon web server 2.0.0.1021 y anteriores permite a atacantes remotos sortear restricciones de acceso de ficheros protegidos mediante una URL cuya porción de directorio acaba en . (punto). | |
| Modificada | Media (5) | 1.6% | — | Working Resources Inc. Badblue | 12/8/2002 | 16/6/2026 | BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end. | |
| Modificada | Alta (7.5) | 1.6% | — | Working Resources Inc. Badblue | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. | |
| Modificada | Media (5) | 38% | 💥 Exploit | Working Resources Inc. Badblue | 25/6/2002 | 16/6/2026 | Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Codeblue | 31/5/2002 | 16/6/2026 | Desbordamiento de búfer en CodeBlue 4 y anteriores, y posíblemente otras versiones, permite a atacantes remotos ejecutar código arbitrario mediante una cadena larga en una respuesta SMTP. | |
| Modificada | Media (5) | 2.4% | — | Blueface Falcon WEB Server | 31/5/2002 | 16/6/2026 | El servidor web Falcon 2.0.0.1020 y anteriores permite a atacantes remotos evitar la autenticación y leer ficheros restringidos mediante una barra extra (/) en la URL pedida. | |
| Modificada | Media (5) | 2.3% | — | Working Resources Inc. Badblue | 22/8/2001 | 16/6/2026 | BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request. | |
| Modificada | Media (6.4) | 3.5% | 💥 Exploit | Working Resources Inc. Badblue | 3/5/2001 | 16/6/2026 | ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Working Resources Inc. Badblue | 3/5/2001 | 16/6/2026 | Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 1.1% | — | Bluestone Sapphire WEB | 11/4/2000 | 16/6/2026 | The Bluestone Sapphire web server allows session hijacking via easily guessable session IDs. | |
| Modificada | Media (5) | 1.3% | — | Blueface Falcon WEB Server | 26/10/1999 | 16/6/2026 | Falcon web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.3% | — | Blue World Communications Lasso CGI | 19/8/1997 | 16/6/2026 | Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files. |