Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.1%—Goahead Webserver6/2/200916/6/2026
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header.
ModificadaMedia (5)1.6%—Goahead Webserver6/2/200916/6/2026
webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data.
ModificadaMedia (5)1.3%—Goahead Webserver6/2/200916/6/2026
The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603.
ModificadaMedia (6.5)3.0%—Apache WebserverTypo316/6/200816/6/2026
TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.
ModificadaMedia (5)2.6%💥 ExploitGoahead Software Fs4104-aw DeviceGoahead Software Goahead Webserver4/3/200816/6/2026
goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603.
ModificadaAlta (10)68%💥 ExploitBOA Webserver17/9/200716/6/2026
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memory locations used for string constants, which allows remote attackers to change the admin password stored in memory via a long username in an HTTP Basic Authentication…
ModificadaMedia (5)3.6%💥 ExploitPlain OLD Webserver12/2/200716/6/2026
Directory traversal vulnerability in the Plain Old Webserver (POW) add-on before 0.0.9 for Mozilla Firefox allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
ModificadaMedia (5)3.4%💥 ExploitAidex Mini-webserver31/12/200616/6/2026
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood of HTTP GET requests, possibly related to display of HTTP log data by the GUI. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.6%—Soft3304 04webserver17/8/200616/6/2026
Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing.
ModificadaMedia (6.8)1.3%—Soft3304 04webserver17/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page, a different vulnerability than CVE-2004-1512.
ModificadaMedia (4.6)0.40%—Savant Webserver8/9/200516/6/2026
Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.
ModificadaMedia (5)1.5%—Yaws Webserver17/6/200516/6/2026
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null).
ModificadaAlta (7.5)3.8%—Newmad Technologies Picowebserver1/6/200516/6/2026
Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.
ModificadaMedia (5)1.6%—Soft3304 04webserver3/5/200516/6/2026
Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.
ModificadaMedia (5)1.5%—Cupidsystems CIS Webserver2/5/200516/6/2026
Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.
ModificadaAlta (7.5)5.4%💥 ExploitSavant Webserver2/5/200516/6/2026
Buffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.
ModificadaMedia (4.3)1.4%—Soft3304 04webserver31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted in the resulting default error page.
ModificadaMedia (5)1.7%—Soft3304 04webserver31/12/200416/6/2026
04WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.
ModificadaMedia (5)1.8%—Soft3304 04webserver31/12/200416/6/2026
04WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.
ModificadaMedia (6.4)1.5%—Mywebserver31/12/200416/6/2026
MyWebServer 1.0.3 allows remote attackers to bypass authentication, modify configuration, and read arbitrary files via a direct HTTP request to (1) /admin or (2) ServerProperties.html.
ModificadaMedia (5)1.2%—Soft3304 04webserver31/12/200416/6/2026
Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).
ModificadaMedia (5)3.1%💥 ExploitPwebserver WEB Server31/12/200416/6/2026
Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (5)1.8%—Soft3304 04webserver31/12/200416/6/2026
Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but continue to hold resources.
ModificadaMedia (5)1.6%—Mywebserver31/12/200416/6/2026
MyWebServer 1.0.3 allows remote attackers to cause a denial of service (application crash) via a large number of connections within a short time.
ModificadaAlta (7.8)3.2%💥 ExploitTwilight WebserverAI31/12/200316/6/2026
Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.
Orbitaley — Vulnerabilidades