Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)8.0%—Apache TomcatCanonical Ubuntu LinuxDebian LinuxRedhat Jboss Enterprise WEB Server+1110/8/201717/6/2026
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default…
ModificadaCrítica (9.8)2.9%—Ecos Embedded WEB Servers17/7/201717/6/2026
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does not ask for any sign of authentication…
ModificadaCrítica (9.1)57%—Apache Http ServerDebian LinuxApple MAC OS XNetapp Oncommand Unified Manager+1113/7/201717/6/2026
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of…
ModificadaCrítica (9.8)2.6%—Codesys WEB Server19/5/201717/6/2026
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow…
ModificadaCrítica (9.8)2.0%—Codesys WEB Server19/5/201717/6/2026
A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by…
ModificadaAlta (7.5)12%—Cesanta Mongoose Embedded WEB Server LibraryCesanta Mongoose OS10/4/201717/6/2026
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary…
AnalizadaCrítica (9.8)90%⚠ Explotación activaApache TomcatCanonical Ubuntu LinuxNetapp 7-mode Transition ToolNetapp Oncommand Insight+156/4/201725/8/2026
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427…
ModificadaAlta (7.5)3.6%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerFedoraproject Fedora26/9/201617/6/2026
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
ModificadaAlta (7.5)95%—Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+51/9/201617/6/2026
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated…
ModificadaAlta (8.1)56%—Apache Http ServerHP System Management HomepageOracle Communications User Data RepositoryOracle Enterprise Manager OPS Center+1619/7/201617/6/2026
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a…
ModificadaAlta (8.8)4.2%—Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+813/3/201617/6/2026
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
ModificadaAlta (7.8)2.1%—Exemys Telemetry WEB Server19/11/201517/6/2026
Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass intended access restrictions by disregarding this header and processing the response body.
ModificadaCrítica (9.8)10%—Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+35/11/201517/6/2026
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
ModificadaBaja (2.1)0.35%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (5)2.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
ModificadaMedia (6.4)1.4%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
ModificadaAlta (10)4.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
ModificadaMedia (4.3)1.9%—OK WEB Server Project OK WEB Server31/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in libahttp/err.c in OkCupid OKWS (OK Web Server) allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to a non-existent page, which is not properly handled in a 404 error page.
ModificadaMedia (4.3)1.5%—Efssoft Easy File Sharing WEB Server2/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registration, which is not properly handled by forum.ghp.
ModificadaMedia (4.3)1.8%—Efssoft Easy File Sharing WEB Server6/8/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Easy File Sharing (EFS) Web Server 6.8 allow remote authenticated users to inject arbitrary web script or HTML via the content parameter when (1) creating a topic or (2) posting an answer. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.4)95%—OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+125/6/201417/6/2026
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive…
ModificadaAlta (10)79%—Efssoft Easy File Sharing WEB Server20/5/201417/6/2026
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.
ModificadaMedia (5)53%—Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+1115/4/201416/6/2026
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
ModificadaAlta (7.5)13%—Redhat Jboss Enterprise Brms PlatformRedhat Jboss Enterprise Portal PlatformRedhat Jboss Enterprise WEB ServerRedhat Openshift+128/10/201316/6/2026
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
ModificadaMedia (6.9)0.37%—Redhat Jboss Enterprise WEB ServerRedhat Enterprise Linux9/7/201316/6/2026
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log,…