Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | An-httpd | 7/4/2005 | 16/6/2026 | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request. | |
| Modificada | Alta (7.5) | 1.1% | — | Christian Hilgers Http Anti Virus Proxy (havp) | 4/3/2005 | 16/6/2026 | Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files. | |
| Modificada | Media (5) | 1.5% | — | Raidenhttpd | 1/3/2005 | 16/6/2026 | RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space. | |
| Modificada | Alta (7.5) | 3.1% | — | Raidenhttpd | 1/3/2005 | 16/6/2026 | Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Media (5) | 1.7% | — | Lighttpd | 16/2/2005 | 16/6/2026 | The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension. | |
| Modificada | Alta (7.8) | 4.8% | 💥 Exploit | Apache Http ServerOpenpkgHp-uxSlackware Linux+2 | 9/2/2005 | 16/6/2026 | Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error. | |
| Modificada | Media (5) | 55% | 💥 Exploit | Apache Http Server | 9/2/2005 | 16/6/2026 | Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters. | |
| Modificada | Alta (10) | 5.6% | — | Cherokee Httpd | 10/1/2005 | 16/6/2026 | Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL. | |
| Modificada | Media (5) | 1.8% | — | Jetty Http Server | 31/12/2004 | 16/6/2026 | HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Cherokee Httpd | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Minishare Minimal Http Server | 31/12/2004 | 16/6/2026 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 2.3% | — | HP SSL Http Server | 31/12/2004 | 16/6/2026 | The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates. | |
| Modificada | Media (5) | 1.5% | — | Minihttpserver.net WEB Forums Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash). | |
| Modificada | Media (5) | 1.2% | — | Mbedthis Software Mbedthis Appweb Http Server | 31/12/2004 | 16/6/2026 | Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access. | |
| Modificada | Alta (7.5) | 2.4% | — | CA Unicenter WEB Services Distributed ManagementIBM Trading Partner InterchangeJetty Http Server | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Omnicron OmnihttpdAI | 31/12/2004 | 16/6/2026 | Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | FreescoAIThttpdAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. | |
| Modificada | Media (5) | 1.7% | — | Mbedthis Software Mbedthis Appweb Http Server | 31/12/2004 | 16/6/2026 | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request. | |
| Modificada | Media (4.3) | 0.94% | — | Minihttpserver.net Forum WEB Server | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm. | |
| Modificada | Media (5) | 1.9% | — | Geovision Geohttpserver | 31/12/2004 | 16/6/2026 | The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Acme Labs Thttpd | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). | |
| Modificada | Media (4.6) | 0.31% | — | Minihttpserver.net WEB Forums ServerAI | 31/12/2004 | 16/6/2026 | Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges. | |
| Modificada | Baja (2.1) | 0.55% | — | Apache Http Server | 31/12/2004 | 16/6/2026 | The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http Server | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration. | |
| Modificada | Media (6.8) | 58% | 💥 Exploit | Oracle Http Server | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request. |