Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)13%💥 ExploitBbshareware.com Phusion Webserver31/5/200216/6/2026
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.
ModificadaMedia (5)1.3%—Nombas Scriptease Webserver31/5/200216/6/2026
ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.
ModificadaMedia (5)8.8%💥 ExploitBbshareware.com Phusion Webserver31/5/200216/6/2026
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.
ModificadaMedia (5)2.5%—Nombas Scriptease Webserver31/5/200216/6/2026
Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.
ModificadaMedia (5)2.8%—Funsoft Dinos Webserver31/5/200216/6/2026
Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.
ModificadaMedia (5)1.8%—Michael Lamont Savant Webserver25/3/200216/6/2026
Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name contains a large number of . (dot) characters.
ModificadaAlta (7.5)2.6%—Funsoft Dinos Webserver25/3/200216/6/2026
Directory traversal vulnerability in Funsoft Dino's Webserver 1.2 and earlier allows remote attackers to read files or execute arbitrary commands via a .. (dot dot) in the URL.
ModificadaMedia (5)14%💥 ExploitGoahead Software Goahead Webserver13/2/200216/6/2026
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed.
ModificadaMedia (5)2.9%—Nombas Scriptease WebserverNovell Netware31/12/200116/6/2026
Directory traversal vulnerability in ScriptEase viewcode.jse for Netware 5.1 before 5.1 SP3 allows remote attackers to read arbitrary files via ".." sequences in the query string.
ModificadaMedia (5)2.2%—ACI 4D Webserver31/8/200116/6/2026
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.
ModificadaAlta (7.5)3.3%—Roxen Webserver2/8/200116/6/2026
A module in Roxen 2.0 before 2.0.92, and 2.1 before 2.1.264, does not properly decode UTF-8, Mac and ISO-2202 encoded URLs, which could allow a remote attacker to execute arbitrary commands or view arbitrary files via an encoded URL.
ModificadaMedia (5)8.4%💥 ExploitGoahead Software Goahead Webserver2/7/200116/6/2026
GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http ServerVwebserver29/6/200116/6/2026
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.
ModificadaMedia (5)1.8%—Vwebserver29/6/200116/6/2026
vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.
ModificadaMedia (5)2.0%—Vwebserver29/6/200116/6/2026
vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).
ModificadaMedia (5)1.3%—Vwebserver29/6/200116/6/2026
vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.
ModificadaAlta (7.5)1.8%—Micheal Lamont Savant Webserver18/6/200116/6/2026
Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.
ModificadaAlta (7.5)1.7%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to read arbitrary files via a webserver root directory set to system root.
ModificadaAlta (7.5)2.5%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
The (1) FTP and (2) Telnet services in Beck GmbH IPC@Chip are shipped with a default password, which allows remote attackers to gain unauthorized access.
ModificadaMedia (5)3.2%—Beck IPC Gmbh IPC AT Chip Embedded-webserver24/5/200116/6/2026
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.
ModificadaMedia (5)1.6%—Beck IPC Gmbh IPC AT Chip Embedded-webserver21/5/200116/6/2026
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.
ModificadaMedia (5)3.6%💥 ExploitGoahead Software Goahead Webserver3/5/200116/6/2026
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.
ModificadaMedia (5)3.0%💥 ExploitA1webserver Http Server3/5/200116/6/2026
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
ModificadaAlta (10)3.3%—A1webserver Http Server3/5/200116/6/2026
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
ModificadaMedia (5)8.4%💥 ExploitBOA Webserver19/12/200023/9/2026
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack in the GET HTTP request that uses a "%2E" instead of a "."
Orbitaley — Vulnerabilidades