Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.35%—Omnisecure Httprotect19/7/200116/6/2026
OmniSecure HTTProtect 1.1.1 allows a superuser without omnish privileges to modify a protected file by creating a symbolic link to that file.
ModificadaMedia (5)1.6%—Doug Neal Dnhttpd3/7/200116/6/2026
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http ServerVwebserver29/6/200116/6/2026
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http Server27/6/200116/6/2026
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
ModificadaMedia (5)12%—Apache Http Server12/5/200116/6/2026
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
ModificadaMedia (5)3.0%💥 ExploitA1webserver Http Server3/5/200116/6/2026
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
ModificadaAlta (7.5)3.7%💥 ExploitBajie Java Http Server3/5/200116/6/2026
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.
ModificadaAlta (7.5)7.9%💥 ExploitBajie Java Http Server3/5/200116/6/2026
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
ModificadaAlta (10)3.3%—A1webserver Http Server3/5/200116/6/2026
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
ModificadaMedia (5)3.3%💥 ExploitIBM Http ServerIBM Websphere Application Server13/3/200116/6/2026
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
ModificadaMedia (5)75%💥 ExploitApache Http ServerDebian Linux12/3/200116/6/2026
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
ModificadaAlta (10)10%💥 ExploitOmnicron Omnihttpd12/3/200116/6/2026
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.
ModificadaBaja (3.3)2.3%—Apache Http ServerDebian Linux12/3/200116/6/2026
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
ModificadaMedia (5)2.2%💥 ExploitOmnicron Omnihttpd12/3/200116/6/2026
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
ModificadaMedia (5)9.6%💥 ExploitApache Http Server16/2/200116/6/2026
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
ModificadaMedia (5)1.2%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
ModificadaAlta (7.5)1.9%—IBM Http Server9/1/200116/6/2026
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
ModificadaMedia (5)1.3%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.
ModificadaMedia (5)3.3%💥 ExploitMAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.
ModificadaMedia (5)36%—Apache Http Server19/12/200023/9/2026
mod_rewrite en Apache 1.3.12 y versiones anteriores permite a atacantes remotos leer archivos arbitrarios si una directiva RewriteRule se expande para incluir un nombre de archivo cuyo nombre contiene una expresión regular.
ModificadaAlta (7.5)2.0%—Acme Labs Thttpd19/12/200023/9/2026
Vulnerabilidad de salto de directorio en el programa CGI ssi en thttpd 2.19 y anteriores permite a atacantes remotos leer archivos arbitrarios mediante una cadena '%2e%2e', una variación del ataque .. (punto punto).
ModificadaMedia (5)51%💥 ExploitApache Http ServerSuse Linux14/11/200016/6/2026
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
ModificadaMedia (5)45%—Apache Http ServerSuse Linux14/11/200016/6/2026
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
ModificadaMedia (5)1.3%—Fastream FUR Http Server14/11/200016/6/2026
Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.
ModificadaMedia (5)1.9%—Bajie Java Http Server20/10/200016/6/2026
Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.
Orbitaley — Vulnerabilidades