Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)4.0%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
ModificadaMedia (5.3)39%💥 ExploitCybrotech Cybrohttpserver29/8/201817/6/2026
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
ModificadaMedia (5.4)0.64%—Simplehttpserver Project Simplehttpserver7/6/201817/6/2026
simplehttpserver node module suffers from a Cross-Site Scripting vulnerability to a lack of validation of file names.
ModificadaAlta (7.5)2.0%—Cypserver Project Cypserver7/6/201817/6/2026
cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaAlta (8.8)3.1%💥 ExploitWampserver25/3/201817/6/2026
Wampserver before 3.1.3 has CSRF in add_vhost.php.
ModificadaMedia (5.4)1.7%💥 ExploitWampserver19/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
ModificadaAlta (7.5)2.1%—Appserver25/7/201717/6/2026
Directory traversal vulnerability in the web request/response interface in Appserver before 1.0.3 allows remote attackers to read normally inaccessible files via a .. (dot dot) in a crafted URL.
ModificadaCrítica (9.8)4.8%—Debian LinuxOsgeo Mapserver15/3/201717/6/2026
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
ModificadaMedia (5.3)0.55%—Wampserver27/12/201617/6/2026
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an…
ModificadaAlta (7.5)1.1%💥 ExploitWampserver27/12/201617/6/2026
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the…
ModificadaAlta (7.5)1.5%—Osgeo Mapserver8/12/201617/6/2026
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
ModificadaMedia (6.8)2.4%—Wftpserver Wing FTP Server10/6/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code via a crafted request to admin_lua_script.html or (2) add a domain administrator via a crafted request to…
ModificadaMedia (6.8)2.2%—Osgeo MapserverUMN Mapserver5/1/201417/6/2026
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
ModificadaAlta (7.8)1.8%—Kepware Kepserverex22/8/201316/6/2026
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite…
ModificadaMedia (6.8)2.2%—Wftpserver Wing FTP Server26/10/201216/6/2026
Wing FTP Server before 4.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via two zip commands.
ModificadaMedia (5.5)1.9%💥 ExploitZftpserver Suite20/12/201116/6/2026
Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary directories via a crafted RMD (aka rmdir) command.
ModificadaMedia (6.8)4.6%💥 ExploitOsgeo MapserverUMN Mapserver1/8/201116/6/2026
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
ModificadaAlta (7.5)5.2%—Osgeo MapserverUMN Mapserver1/8/201116/6/2026
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
ModificadaAlta (7.5)2.7%—Osgeo MapserverUMN Mapserver1/8/201116/6/2026
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
ModificadaMedia (4.3)4.9%💥 ExploitBlackmoonftpserver Blackmoon FTP Server20/1/201116/6/2026
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to cause a denial of service (crash) via a large number of PORT commands with long arguments, which triggers a NULL pointer dereference. NOTE: some of these details are…
ModificadaAlta (10)3.8%—Osgeo MapserverUMN Mapserver2/8/201016/6/2026
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
ModificadaBaja (2.1)0.32%—Osgeo MapserverUMN Mapserver2/8/201016/6/2026
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.
ModificadaMedia (4.3)2.0%—Wftpserver Wing FTP Server24/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted POST request.
ModificadaMedia (4.3)1.7%💥 ExploitWampserver23/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
ModificadaAlta (10)5.9%—Osgeo MapserverUMN Mapserver23/10/200916/6/2026
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a…
Orbitaley — Vulnerabilidades