Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.7%—Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+118/2/201316/6/2026
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical…
ModificadaMedia (4.3)1.6%—Litespeedtech Litespeed WEB Server6/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.
ModificadaAlta (7.5)1.4%—Siemens Synco OZW WEB ServerSiemens Synco OZW WEB Server Firmware6/8/201216/6/2026
The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.
ModificadaMedia (5)2.7%—Oracle Iplanet WEB ServerOracle SUN Products Suite Java System WEB Server17/7/201216/6/2026
Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server.
ModificadaMedia (4.3)1.5%—Sphinx-soft Mobile WEB Server7/2/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt.
ModificadaMedia (4.3)82%—Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+728/1/201216/6/2026
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with…
ModificadaMedia (4.6)2.8%—Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+818/1/201216/6/2026
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
ModificadaMedia (4.3)22%—Apache Http ServerRedhat Jboss Enterprise WEB Server20/9/201116/6/2026
The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request.
ModificadaMedia (5)1.1%—Nessus WEB Server Plugin10/8/201016/6/2026
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response.
ModificadaMedia (4.3)1.6%—Nessus WEB Server Plugin30/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)60%—Litespeedtech Litespeed WEB Server18/6/201016/6/2026
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
ModificadaAlta (7.5)1.4%—Accoria Rock WEB Server15/6/201016/6/2026
Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter.
ModificadaAlta (7.5)1.4%—Accoria Rock WEB Server15/6/201016/6/2026
Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.
ModificadaMedia (5)1.7%—Accoria Rock WEB Server15/6/201016/6/2026
Directory traversal vulnerability in loadstatic.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.
ModificadaMedia (6.8)0.61%—Accoria Rock WEB Server15/6/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to hijack the authentication of administrators for requests that create user accounts.
ModificadaMedia (4.3)0.94%—Accoria Rock WEB Server15/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the getenv sample program, (2) the desc parameter to loadstatic.cgi, (3) the name parameter to httpdcfg.cgi, or (4) the dns…
ModificadaMedia (5)2.8%—Sharing-file Easy File Sharing WEB Server23/4/201016/6/2026
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter.
ModificadaMedia (5)1.6%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
ModificadaAlta (7.5)3.0%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.
ModificadaMedia (4.3)1.4%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.
ModificadaMedia (5)1.6%—SUN ONE WEB Server25/2/201016/6/2026
Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.
ModificadaMedia (5)1.2%—SUN ONE WEB Server25/2/201016/6/2026
Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.
ModificadaMedia (4.3)0.89%—SUN ONE WEB Server5/2/201016/6/2026
Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level…
ModificadaMedia (4.3)1.1%—SUN ONE WEB Server5/2/201016/6/2026
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format="…
ModificadaBaja (2.6)1.1%—SUN ONE WEB Server5/2/201016/6/2026
Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a…