Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

841 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.1%—Cambridge Computer Corporation Vxweb22/9/200516/6/2026
Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
ModificadaMedia (4.3)1.2%—Burton Computer Corporation Spamprobe31/12/200316/6/2026
SpamProbe 0.8a allows remote attackers to cause a denial of service (crash) via HTML e-mail with newline characters within an href tag, which is not properly handled by certain regular expressions.
ModificadaBaja (2.1)0.35%—MDG Computer Services WEB Server 4D2/4/200316/6/2026
Web Server 4d (WS4D) 3.6 almacena contraseñas en texto plano en el fichero Ws4d.4DD, lo que permite a atacantes ganar privilegios.
ModificadaMedia (5)1.8%—Summit Computer Networks LIL Http31/12/200216/6/2026
Directory traversal vulnerability in Lil' HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
ModificadaAlta (7.5)7.0%💥 ExploitSummit Computer Networks LIL Http Server4/10/200216/6/2026
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.
ModificadaAlta (7.5)7.1%💥 ExploitSummit Computer Networks LIL Http Server4/10/200216/6/2026
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.
ModificadaMedia (5)1.5%—Summit Computer Networks LIL Http Server31/5/200216/6/2026
Lil HTTP Server 2.1 permite a atacantes remotos leer ficheros protegidos por contraseña mediante un /./ (barra punto barra) en la petición HTTP.
ModificadaAlta (7.5)3.3%—MDG Computer Services WEB Server 4D Ecommerce25/3/200216/6/2026
MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 y anteriores, y posiblemente 3.5.3, permiten a atacantes remotos causar negaciones de servicio y posiblemente ejecutar comandos arbitrarios vía peticiones largas HTTP.
ModificadaMedia (5)2.0%—MDG Computer Services WEB Server 4D Ecommerce25/3/200216/6/2026
MDG Computer Services Web Server WS4D/eCommerce 3.5.3, permite a atacantes remotos explotar directorios via ../ conteniendo / en la parte codificada de la peticion HTTP.
ModificadaAlta (7.5)4.6%—Peaceworks Computer Consulting Phormation2/10/200116/6/2026
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
ModificadaMedia (5)6.2%💥 ExploitComputer Software Manufaktur Alibaba18/7/200016/6/2026
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
ModificadaMedia (4.6)0.34%—Computer Power Solutions Visual Casel17/1/200016/6/2026
Visual Casel (Vcasel) does not properly prevent users from executing files, which allows local users to use a relative pathname to specify an alternate file which has an approved name and possibly gain privileges.
ModificadaMedia (5)1.1%—Computer Software Manufaktur Alibaba31/12/199916/6/2026
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.
ModificadaBaja (3.6)2.8%💥 ExploitComputer Software Manufaktur Alibaba3/11/199916/6/2026
El servidor web Alibaba permite a un atacante remoto ejecutar comandos mediante un caráctar de tubería (barra vertical) en una URL malformada.
ModificadaMedia (5)1.4%—Computer Software Manufaktur Alibaba12/5/199916/6/2026
Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.
ModificadaMedia (5)1.4%—Computer Software Manufaktur CSM Proxy16/7/199816/6/2026
Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.