Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header. | |
| Modificada | Media (5) | 1.6% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data. | |
| Modificada | Media (5) | 1.3% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603. | |
| Modificada | Media (6.5) | 3.0% | — | Apache WebserverTypo3 | 16/6/2008 | 16/6/2026 | TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Goahead Software Fs4104-aw DeviceGoahead Software Goahead Webserver | 4/3/2008 | 16/6/2026 | goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603. | |
| Modificada | Alta (10) | 68% | 💥 Exploit | BOA Webserver | 17/9/2007 | 16/6/2026 | The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication… | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Plain OLD Webserver | 12/2/2007 | 16/6/2026 | Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Aidex Mini-webserver | 31/12/2006 | 16/6/2026 | AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood of HTTP GET requests, possibly related to display of HTTP log data by the GUI. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.6% | — | Soft3304 04webserver | 17/8/2006 | 16/6/2026 | Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing. | |
| Modificada | Media (6.8) | 1.3% | — | Soft3304 04webserver | 17/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page, a different vulnerability than CVE-2004-1512. | |
| Modificada | Media (4.6) | 0.40% | — | Savant Webserver | 8/9/2005 | 16/6/2026 | Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.5% | — | Yaws Webserver | 17/6/2005 | 16/6/2026 | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null). | |
| Modificada | Alta (7.5) | 3.8% | — | Newmad Technologies Picowebserver | 1/6/2005 | 16/6/2026 | Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL. | |
| Modificada | Media (5) | 1.6% | — | Soft3304 04webserver | 3/5/2005 | 16/6/2026 | Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder. | |
| Modificada | Media (5) | 1.5% | — | Cupidsystems CIS Webserver | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL. | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Savant Webserver | 2/5/2005 | 16/6/2026 | Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request. | |
| Modificada | Media (4.3) | 1.4% | — | Soft3304 04webserver | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page. | |
| Modificada | Media (5) | 1.7% | — | Soft3304 04webserver | 31/12/2004 | 16/6/2026 | 04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries. | |
| Modificada | Media (5) | 1.8% | — | Soft3304 04webserver | 31/12/2004 | 16/6/2026 | 04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2. | |
| Modificada | Media (6.4) | 1.5% | — | Mywebserver | 31/12/2004 | 16/6/2026 | MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html. | |
| Modificada | Media (5) | 1.2% | — | Soft3304 04webserver | 31/12/2004 | 16/6/2026 | Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code). | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Pwebserver WEB Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (5) | 1.8% | — | Soft3304 04webserver | 31/12/2004 | 16/6/2026 | Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources. | |
| Modificada | Media (5) | 1.6% | — | Mywebserver | 31/12/2004 | 16/6/2026 | MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time. | |
| Modificada | Alta (7.8) | 3.2% | 💥 Exploit | Twilight WebserverAI | 31/12/2003 | 16/6/2026 | Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376. |