Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Myproxy | 11/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Alta (10) | 41% | — | Microsoft Proxy Server | 17/2/2004 | 16/6/2026 | Desbordamiento de búfer en el filtro H.323 Microsoft Internet Security and Acceleration Server 2000 permite a atacantes remotos ejecutar código arbitrario en el Servicio de Cortafuegos de Microsoft mediante cierto tráfico H.323, como se demostró por por la suite de pruebas del protocolo H.225 NISCC/OUSPG PROTOS. | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | |
| Modificada | Alta (10) | 2.2% | — | Replicom Proxyview | 31/12/2003 | 16/6/2026 | ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access. | |
| Modificada | Alta (7.5) | 4.6% | — | Realnetworks Realsystem ProxyRealnetworks Realsystem Server | 31/12/2003 | 16/6/2026 | Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 1.7% | — | Plug AND Play WEB Server Proxy | 31/10/2003 | 16/6/2026 | Plug and Play Web Server Proxy 1.0002c allows remote attackers to cause a denial of service (server crash) via an invalid URI in an HTTP GET request to TCP port 8080. | |
| Modificada | Alta (10) | 6.8% | — | Analogx Proxy | 30/6/2003 | 16/6/2026 | Desbordamiento de búfer en AnalogX Proxy 4.13 permite a atacantes remotos ejecutar código arbitrario mediante una URL larga al puerto 6588 | |
| Modificada | Media (5) | 18% | — | Microsoft ISA ServerMicrosoft Proxy Server | 5/5/2003 | 16/6/2026 | El servicio Winsock Proxy en Microsoft Proxy Server 2.0 y el servicio Microsoft Firewall en Internet Security and Acceleration (ISA) Server 2000 permite a atacantes remotos causar una denegación de servicio (consumición de cpu o tormenta de paquetes) mediante paquetes malformados, al puerto UDP 1745. | |
| Modificada | Media (4.3) | 1.1% | — | Acfp Project Acfreeproxy | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in acFreeProxy (aka acFP) 1.33 beta 7 allows remote attackers to inject arbitrary web script or HTML via the URL, which is inserted into an error page. | |
| Modificada | Alta (10) | 4.5% | — | Multi-tech Proxyserver | 31/12/2002 | 16/6/2026 | Multi-Tech ProxyServer products MTPSR1-100, MTPSR1-120, MTPSR1-202ST, MTPSR2-201, and MTPSR3-200 ship with a null password, which allows remote attackers to gain administrative privileges via Telnet or HTTP. | |
| Modificada | Media (5) | 1.4% | — | Apt-www-proxy | 31/12/2002 | 16/6/2026 | The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which causes a null dereference. | |
| Modificada | Media (5) | 2.7% | — | HP Praesidium Webproxy | 31/12/2002 | 16/6/2026 | HP Praesidium Webproxy 1.0 running on HP-UX 11.04 VVOS could allow remote attackers to cause Webproxy to forward requests to the internal network via crafted HTTP requests. | |
| Modificada | Alta (10) | 4.8% | — | Apt-www-proxy | 31/12/2002 | 16/6/2026 | Format string vulnerability in the awp_log function in apt-www-proxy 0.1 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | IBM Websphere Caching Proxy Server | 4/11/2002 | 16/6/2026 | IBM Web Traffic Express Caching Proxy Server 3.6 y 4.x antes de 4.0.1.26 permite atacantes remotso causar una denegación de servicio (caída) mediante una petición HTTP a helpout.exe sin número de versión HTTP, lo que hace que ibmproxy.exe se caiga. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | IBM Websphere Caching Proxy Server | 4/11/2002 | 16/6/2026 | Vulnerabilidad scripts en sitios cruzados en IBM Web Traffic Express Caching Proxy Server 3.6 y 3.x anteriores a 4.0.1.26 permite a atacantes remotos ejecutar código como otros mediante una petición HTTP GET. | |
| Modificada | Media (6.8) | 1.6% | 💥 Exploit | IBM Websphere Caching Proxy Server | 4/11/2002 | 16/6/2026 | Vulnerabiliad de scripts en sitios cruzados (XSS) en IBM Web Traffic Express Caching Proxy Server 3.6 y 4.x anteriores a 4.0.1.26 permite a atacantes remotos ejecutar código como otros usuarios mediante una petición HTTP que contiene una cabecera Location: con una secuencia "%0a%0d" (CRLF), lo que de vuelve la… | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | Analogx Proxy | 4/10/2002 | 16/6/2026 | Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname. | |
| Modificada | Alta (7.5) | 2.8% | — | Tinyproxy | 12/8/2002 | 16/6/2026 | tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free). | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft ISA ServerMicrosoft Proxy ServerUniversity OF Minnesota Gopher | 3/7/2002 | 16/6/2026 | Desbordamiento de búfer en el cliente gopher de Microsoft Internet Explorer 5.1 a la 6.0, Proxy Server 2.0, o ISA Server 2000 permite a atacantes remotos la ejecución de código arbitrario mediante una URL gopher:// que redirige al usuario a un servidor gopher real o simulado que envía una respuesta larga. | |
| Modificada | Alta (7.2) | 0.25% | — | Bindview NetrcFunk Software Proxy | 22/4/2002 | 16/6/2026 | Funk Software Proxy Host 3.x usa cifrado débil para la contraseña de Proxy Host, lo que permite a usuarios locales ganar privilegios desde le fichero PHOST.INI o el registro de Windows. | |
| Modificada | Alta (7.2) | 0.37% | — | Bindview NetrcFunk Software Proxy | 22/4/2002 | 16/6/2026 | Funk Software Proxy Host 3.x se instala con permisos inseguros para el registro y el sistema de ficheros. | |
| Modificada | Alta (7.5) | 1.6% | — | Bindview NetrcFunk Software Proxy | 22/4/2002 | 16/6/2026 | Funk Software Proxy Host 3.x anterior a 3.09a crea un tubería con nombre (Named Pipe) que no requiere autentificación y se instala con control de acceso inseguro, lo que permite a usuarios locales y posiblemente remotos usar las utilidades de configuración del Proxy Host y ganar privilegios. | |
| Modificada | Media (5) | 2.8% | — | Squid WEB Proxy | 6/12/2001 | 16/6/2026 | Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request. | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Tinyproxy | 12/3/2001 | 16/6/2026 | Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long connect request. |