Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.5%—Sharing-file Easy File Sharing WEB Server13/5/201917/6/2026
An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)3.2%—Rockwellautomation Ethernet/ip WEB Server Module 1756-ewebRockwellautomation Ethernet/ip WEB Server Module 1768-eweb27/3/201917/6/2026
Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the SNMP service causing a denial-of-service condition to occur until the affected product is…
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaMedia (5.3)0.96%—3CX WEB Server3/8/201817/6/2026
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname.
ModificadaMedia (6.1)0.69%—3CX WEB Server3/8/201817/6/2026
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.
ModificadaMedia (6.1)0.69%—3CX WEB Server3/8/201817/6/2026
The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.
ModificadaAlta (7.5)21%—Apache TomcatRedhat Jboss Enterprise Application PlatformCanonical Ubuntu LinuxDebian Linux+42/8/201817/6/2026
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
ModificadaCrítica (9.8)77%—Sharing-file Easy File Sharing WEB Server20/4/201817/6/2026
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp. NOTE: this may overlap CVE-2014-3791.
ModificadaMedia (5.9)17%—Apache TomcatRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerDebian Linux+628/2/201817/6/2026
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore,…
ModificadaCrítica (9.8)3.1%—3s-software Codesys Runtime System3s-software Codesys WEB Server15/2/201817/6/2026
A Stack-based Buffer Overflow issue was discovered in 3S-Smart CODESYS Web Server. Specifically: all Microsoft Windows (also WinCE) based CODESYS web servers running stand-alone Version 2.3, or as part of the CODESYS runtime system running prior to Version V1.1.9.19. A crafted request may cause a buffer overflow and…
ModificadaAlta (7.5)7.9%—Embedthis Goahead WEB Server3/1/201817/6/2026
EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.
ModificadaCrítica (9.8)13%—Dbltek WEB Server24/11/201717/6/2026
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call…
ModificadaCrítica (9.8)86%—Redhat Data GridRedhat Jboss A-mqRedhat Jboss BPM SuiteRedhat Jboss Data Virtualization+119/11/201717/6/2026
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat…
ModificadaAlta (7.1)1.7%—Apache Portable RuntimeDebian LinuxRedhat Jboss Core ServicesRedhat Jboss Enterprise WEB Server+724/10/201717/6/2026
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting…
ModificadaMedia (6.1)1.4%—Oracle Iplanet WEB Server19/10/201717/6/2026
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server.…
AnalizadaAlta (8.1)100%⚠ Explotación activaApache TomcatCanonical Ubuntu LinuxOracle Agile Product Lifecycle ManagementOracle Communications Instant Messaging Server+544/10/201725/8/2026
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP…
ModificadaAlta (7.5)1.2%—Redhat AMQRedhat Jboss Enterprise WEB Server25/9/201717/6/2026
Console: CORS headers set to allow all in Red Hat AMQ.
ModificadaAlta (7.5)2.2%—Redhat AMQRedhat Jboss A-mqRedhat Jboss Enterprise WEB Server25/9/201717/6/2026
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.
AnalizadaAlta (8.1)100%⚠ Explotación activaApache TomcatNetapp 7-mode Transition ToolNetapp Oncommand BalanceNetapp Oncommand Shift+1819/9/20176/8/2026
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed…
ModificadaAlta (8.8)4.1%—Cesanta Mongoose Embedded WEB Server Library7/9/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.
ModificadaAlta (7.5)3.8%—Spidercontrol Scada WEB Server25/8/201717/6/2026
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
ModificadaAlta (7.5)8.3%—Apache TomcatDebian LinuxNetapp Oncommand InsightNetapp Oncommand Shift+1111/8/201717/6/2026
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
ModificadaAlta (7.5)8.1%—Apache TomcatOracle Tekelec Platform DistributionDebian LinuxNetapp Oncommand Insight+1010/8/201717/6/2026
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web…
ModificadaMedia (5.3)7.2%—Apache TomcatDebian LinuxRedhat Jboss Enterprise WEB ServerRedhat Enterprise Linux Desktop+1010/8/201717/6/2026
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be…
ModificadaCrítica (9.1)10%—Apache TomcatNetapp Oncommand InsightNetapp Oncommand ShiftNetapp Snap Creator Framework+1110/8/201717/6/2026
In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.