Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)2.3%💥 ExploitAn-httpd7/4/200516/6/2026
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.
ModificadaAlta (7.5)1.1%—Christian Hilgers Http Anti Virus Proxy (havp)4/3/200516/6/2026
Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.
ModificadaMedia (5)1.5%—Raidenhttpd1/3/200516/6/2026
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.
ModificadaAlta (7.5)3.1%—Raidenhttpd1/3/200516/6/2026
Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.
ModificadaMedia (5)1.7%—Lighttpd16/2/200516/6/2026
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
ModificadaAlta (7.8)4.8%💥 ExploitApache Http ServerOpenpkgHp-uxSlackware Linux+29/2/200516/6/2026
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
ModificadaMedia (5)55%💥 ExploitApache Http Server9/2/200516/6/2026
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.
ModificadaAlta (10)5.6%—Cherokee Httpd10/1/200516/6/2026
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
ModificadaMedia (5)1.8%—Jetty Http Server31/12/200416/6/2026
HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.
ModificadaMedia (4.3)3.6%💥 ExploitCherokee Httpd31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.
ModificadaAlta (7.5)72%💥 ExploitMinishare Minimal Http Server31/12/200416/6/2026
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)2.3%—HP SSL Http Server31/12/200416/6/2026
The SSL HTTP Server in HP Web-enabled Management Software 5.0 through 5.92, with anonymous access enabled, allows remote attackers to compromise the trusted certificates by uploading their own certificates.
ModificadaMedia (5)1.5%—Minihttpserver.net WEB Forums Server31/12/200416/6/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModificadaMedia (5)1.2%—Mbedthis Software Mbedthis Appweb Http Server31/12/200416/6/2026
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message that is generated when Mbedthis denies access.
ModificadaAlta (7.5)2.4%—CA Unicenter WEB Services Distributed ManagementIBM Trading Partner InterchangeJetty Http Server31/12/200416/6/2026
Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaAlta (7.5)10%💥 ExploitOmnicron OmnihttpdAI31/12/200416/6/2026
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.
ModificadaMedia (4.3)1.4%💥 ExploitFreescoAIThttpdAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.
ModificadaMedia (5)1.7%—Mbedthis Software Mbedthis Appweb Http Server31/12/200416/6/2026
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.
ModificadaMedia (4.3)0.94%—Minihttpserver.net Forum WEB Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModificadaMedia (5)1.9%—Geovision Geohttpserver31/12/200416/6/2026
The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow.
ModificadaMedia (5)3.6%💥 ExploitAcme Labs Thttpd31/12/200416/6/2026
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
ModificadaMedia (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI31/12/200416/6/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModificadaBaja (2.1)0.55%—Apache Http Server31/12/200416/6/2026
The check_forensic script in apache-utils package 1.3.31 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.5)7.6%—Apache Http Server31/12/200416/6/2026
Unknown vulnerability in Apache 2.0.51 prevents "the merging of the Satisfy directive," which could allow attackers to obtain access to restricted resources contrary to the specified authentication configuration.
ModificadaMedia (6.8)58%💥 ExploitOracle Http Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, or (3) password parameters in an isqlplus request.
Orbitaley — Vulnerabilidades