Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)7.6%💥 ExploitHughes Technologies Libhttpd31/12/200216/6/2026
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request.
ModificadaAlta (7.5)10%💥 ExploitLonerunner Zeroo Http Server31/12/200216/6/2026
Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request.
ModificadaMedia (5)6.0%—Apache Http Server31/12/200216/6/2026
Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request.
ModificadaMedia (5)2.1%—IBM Http Server31/12/200216/6/2026
IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP).
ModificadaCrítica (9.8)9.0%💥 ExploitRedshift Atphttpd31/12/200216/6/2026
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)23%💥 ExploitApache Http Server31/12/200216/6/2026
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.
ModificadaMedia (5)6.1%—Apache Http Server31/12/200216/6/2026
Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities.
ModificadaAlta (7.8)9.7%💥 ExploitApache Http ServerApache Tomcat31/12/200216/6/2026
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
ModificadaBaja (2.6)0.56%—Apache Http Server4/11/200216/6/2026
Apache 1.3.27 y anteriores, y posiblemente versiones posteriores, puede permitir a usuarios locales leer o modificar el fichero de contraseñas de Apache mediante un ataque de enlaces simbólicos en ficheros temporales cuando el administrador de Apache corre htpasswd o htdigest.
ModificadaAlta (7.2)0.94%—Apache Http ServerDebian Linux11/10/200216/6/2026
La tabla de puntuaciones (scoreboard) en memoria compartida del demonio HTTP en Apache 1.3.x anteriores a 1.3.27 permite a cualquier usuario corriendo con la UID de Apache enviar un señas SIGUSR1 a cualquier proceso como root, resultando en un a denegación de servicio (muerte de proceso) o posiblemente otros…
ModificadaMedia (5)9.5%💥 ExploitJetty Http Server11/10/200216/6/2026
Vulnerabilidad de atravesamiento de directorios en el CGIServlet en Jetty HHTP server anteriores a 4.1.0 permite a atacantes remotos leer ficheros arbitrarios mediante secuencias .. (punto punto barra invertida) en peticiones HTTP al directorio cgi-bin.
ModificadaMedia (6.8)95%💥 ExploitApache Http ServerOracle Application ServerOracle Database ServerOracle8i+111/10/200216/6/2026
Vulnerabilidad de comandos en sitios cruzados (cross-site scripting, XSS) en la página de error por defecto en Apache 2.0 antes de 2.0.43, y en 1.3.x hasta 1.3.26, cuando el parámetro UseCanonicalName está desactivado, y está presente el soporte para comodines DNS, permite a atacantes ejecutar comandos como otro…
ModificadaMedia (5)15%—Apache Http Server11/10/200216/6/2026
Apache 2.0.42 permite a atacanes remotos ver el código fuente de un guión (script) CGI mediante una petición POST a un directorio con WebDAV y CGI activados.
ModificadaAlta (7.5)21%—Apache Http ServerOracle Application ServerOracle Database ServerOracle8i11/10/200216/6/2026
Desbordamientos de búfer en el programa de soporte ApacheBench (ab.c) en Apache anteriores a 1.3.27, y Apache 2.x anteriores a 2.0.43, permite a un servidor web malicioso causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante una respuesta larga.
ModificadaAlta (7.5)7.0%💥 ExploitSummit Computer Networks LIL Http Server4/10/200216/6/2026
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.
ModificadaMedia (5)1.6%—Omnicron Omnihttpd4/10/200216/6/2026
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
ModificadaAlta (7.5)7.1%💥 ExploitSummit Computer Networks LIL Http Server4/10/200216/6/2026
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.
ModificadaMedia (5)7.0%—Apache Http Server25/9/200216/6/2026
mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module.
ModificadaMedia (5)59%💥 ExploitApache Http Server5/9/200216/6/2026
Apache 2.0 a 2.0.39 en Windows, OS2 y Netware, permite a atacantes remotos determinar la ruta completa del servidor mediante una petición de un fichero .var, donde el mensaje de error muestra muestra la ruta al archivo, o mediante un mensaje de error que ocurre cuando un script (proceso hijo) no puede ser invocado.
ModificadaAlta (7.5)8.0%💥 ExploitAcme Labs Thttpd12/8/200216/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados en thttpd 2.20 y anteriores permite a atacantes remotos la ejecución arbitraria de rutinas mediante una URL a una página inexistente, lo cual provoca que thttpd inserte la rutina en un mensaje de error 404.
ModificadaAlta (7.5)70%💥 ExploitApache Http Server12/8/200216/6/2026
Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters.
ModificadaMedia (5)36%💥 ExploitOpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
La librería ASN1 de Open SSL 0.9.6d y anterior, y 0.9.7-beta2 y anterior, permite que atacantes remotos provoquen una denegación de servicio por medio de codificaciones inválidas.
ModificadaMedia (4.3)3.9%💥 ExploitW3C Cern Httpd12/8/200216/6/2026
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.
ModificadaAlta (7.5)90%💥 ExploitOpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
Desbordamiento de búfer en OpenSSL 0.9.6d y anteriores, y 0.9.7-beta2 y anteriores, permite a atacantes remotos ejecutar código arbitrario mediante una clave maestra de cliente larga en SSL2 o un ID de sesión largo en SSL3
ModificadaAlta (7.5)8.2%—OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+112/8/200216/6/2026
OpenSSL 0.9.6.d y anteriores, y 0.9.7-beta2 y anteriores, no manejan adecuadamente las representaciones ASCII de enteros en plataformas de 64 bits, lo que podría permitir a atacantes causar una denegación de servicio y posiblemente ejecutar código arbitrario.
Orbitaley — Vulnerabilidades