Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 25% | 💥 Exploit | Microsoft Internet Information Server | 1/1/1999 | 16/6/2026 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | |
| Modificada | Media (5) | 7.6% | — | C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+9 | 26/6/1998 | 16/6/2026 | Information from SSL-encrypted sessions via PKCS #1. | |
| Modificada | Media (5) | 65% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Windows NT | 1/6/1998 | 16/6/2026 | In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. | |
| Modificada | Alta (7) | 19% | — | Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Personal WEB ServerNetscape Enterprise Server+1 | 6/2/1998 | 16/6/2026 | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | |
| Modificada | Media (6.4) | 53% | 💥 Exploit | Microsoft Internet Information Server | 1/9/1997 | 16/6/2026 | IIS newdsn.exe CGI script allows remote users to overwrite files. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/6/1997 | 16/6/2026 | Denial of service in IIS using long URLs. | |
| Modificada | Alta (7.5) | 8.0% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/1/1997 | 16/6/2026 | IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. |