Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.9%—Telcondex Simplewebserver29/10/200316/6/2026
Buffer overflow in TelCondex SimpleWebServer 2.12.30210 Build3285 allows remote attackers to execute arbitrary code via a long HTTP Referer header.
ModificadaMedia (5)1.7%—Mywebserver9/6/200316/6/2026
MyWebServer 1.0.2 allows remote attackers to determine the absolute path of the web document root via a request for a directory that does not exist, which leaks the pathname in an error message.
ModificadaMedia (5)1.9%—Radiobird Software Webserver 4 Everyone2/4/200316/6/2026
Directory traversal vulnerability in WebServer 4 Everyone 1.22 allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a URL.
ModificadaAlta (7.5)5.8%💥 ExploitGoahead Software Goahead Webserver31/12/200216/6/2026
Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories.
ModificadaMedia (5.1)6.8%—Activxperts Software ActivwebserverMicrosoft Windows 2003 Server31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in ActiveXperts Software ActiveWebserver allows remote attackers to execute arbitrary web script via a link.
ModificadaMedia (5)3.4%💥 ExploitMywebserver31/12/200216/6/2026
MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow.
ModificadaMedia (5)2.1%—JO Webserver31/12/200216/6/2026
jo! jo Webserver 1.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
ModificadaMedia (5)1.2%—Soft3304 04webserver31/12/200216/6/2026
Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.
ModificadaMedia (5)3.2%💥 ExploitTelcondex Simplewebserver31/12/200216/6/2026
TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
ModificadaMedia (5)6.9%💥 ExploitSavant Webserver31/12/200216/6/2026
Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negative Content-Length value.
ModificadaAlta (7.5)7.7%💥 ExploitSavant Webserver31/12/200216/6/2026
Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a '.' (%2e) at the end of the filename.
ModificadaAlta (7.5)2.6%—Savant Webserver31/12/200216/6/2026
cgitest.exe in Savant Web Server 3.1 and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request.
ModificadaMedia (5)1.9%—Radiobird Software Webserver 4 ALL28/10/200216/6/2026
Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".." (dot-dot) sequences containing URL-encoded forward slash ("%2F") characters.
ModificadaMedia (5)1.8%—Radiobird Software Webserver 4 ALL28/10/200216/6/2026
Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
ModificadaMedia (5)1.8%—Funsoft Dinos Webserver4/10/200216/6/2026
Encoded directory traversal vulnerability in Dino's web server 2.1 allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f") or (2) "\" (%5c) characters.
ModificadaAlta (7.5)3.2%—ACI 4D Webserver4/10/200216/6/2026
Buffer overflow in 4D web server 6.7.3 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request.
ModificadaAlta (7.5)3.2%—Mywebserver4/10/200216/6/2026
Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)5.1%💥 ExploitMywebserver14/8/200216/6/2026
Buffer overflow in the search capability for MyWebServer 1.0.2 allows remote attackers to execute arbitrary code via a long searchTarget parameter.
ModificadaMedia (4.3)3.9%💥 ExploitMywebserver14/8/200216/6/2026
Cross-site scripting (XSS) vulnerability in MyWebServer 1.0.2 allows remote attackers to insert script and HTML via a long request followed by the malicious script, which is echoed back to the user in an error message.
ModificadaMedia (5)2.0%—Lysias Lidik Webserver12/8/200216/6/2026
Directory traversal vulnerability in Lysias Lidik web server 0.7b allows remote attackers to list directories via an HTTP request with a ... (modified dot dot).
ModificadaMedia (5)3.5%💥 ExploitGoahead Software Goahead WebserverOrange Software Orange WEB ServerMontavista Software Hard HAT Linux23/7/200216/6/2026
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228.
ModificadaAlta (7.5)8.3%💥 ExploitGoahead Software Goahead Webserver23/7/200216/6/2026
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script.
ModificadaMedia (5)4.3%—Deep Forest Software Quik-serv Webserver3/7/200216/6/2026
Directory traversal vulnerability in Quik-Serv HTTP server 1.1B allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.
ModificadaMedia (5)1.2%—Nombas Scriptease Webserver25/6/200216/6/2026
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.
ModificadaAlta (7.5)3.5%—ACI 4D Webserver18/6/200216/6/2026
Buffer overflow in 4D WebServer 6.7.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP request with Basic Authentication containing a long (1) user name or (2) password.
Orbitaley — Vulnerabilidades