Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.7% | — | Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+11 | 8/2/2013 | 16/6/2026 | The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical… | |
| Modificada | Media (4.3) | 1.6% | — | Litespeedtech Litespeed WEB Server | 6/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens Synco OZW WEB ServerSiemens Synco OZW WEB Server Firmware | 6/8/2012 | 16/6/2026 | The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session. | |
| Modificada | Media (5) | 2.7% | — | Oracle Iplanet WEB ServerOracle SUN Products Suite Java System WEB Server | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server. | |
| Modificada | Media (4.3) | 1.5% | — | Sphinx-soft Mobile WEB Server | 7/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sphinx Software Mobile Web Server 3.1.2.47 allow remote attackers to inject arbitrary web script or HTML via the comment parameter to a blog, as demonstrated using (1) Blog/MyFirstBlog.txt or (2) Blog/AboutSomething.txt. | |
| Modificada | Media (4.3) | 82% | — | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+7 | 28/1/2012 | 16/6/2026 | protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with… | |
| Modificada | Media (4.6) | 2.8% | — | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+8 | 18/1/2012 | 16/6/2026 | scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function. | |
| Modificada | Media (4.3) | 22% | — | Apache Http ServerRedhat Jboss Enterprise WEB Server | 20/9/2011 | 16/6/2026 | The mod_proxy_ajp module in the Apache HTTP Server before 2.2.21, when used with mod_proxy_balancer in certain configurations, allows remote attackers to cause a denial of service (temporary "error state" in the backend server) via a malformed HTTP request. | |
| Modificada | Media (5) | 1.1% | — | Nessus WEB Server Plugin | 10/8/2010 | 16/6/2026 | nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response. | |
| Modificada | Media (4.3) | 1.6% | — | Nessus WEB Server Plugin | 30/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 60% | — | Litespeedtech Litespeed WEB Server | 18/6/2010 | 16/6/2026 | LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension. | |
| Modificada | Alta (7.5) | 1.4% | — | Accoria Rock WEB Server | 15/6/2010 | 16/6/2026 | Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Accoria Rock WEB Server | 15/6/2010 | 16/6/2026 | Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. | |
| Modificada | Media (5) | 1.7% | — | Accoria Rock WEB Server | 15/6/2010 | 16/6/2026 | Directory traversal vulnerability in loadstatic.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter. | |
| Modificada | Media (6.8) | 0.61% | — | Accoria Rock WEB Server | 15/6/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to hijack the authentication of administrators for requests that create user accounts. | |
| Modificada | Media (4.3) | 0.94% | — | Accoria Rock WEB Server | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the getenv sample program, (2) the desc parameter to loadstatic.cgi, (3) the name parameter to httpdcfg.cgi, or (4) the dns… | |
| Modificada | Media (5) | 2.8% | — | Sharing-file Easy File Sharing WEB Server | 23/4/2010 | 16/6/2026 | Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter. | |
| Modificada | Media (5) | 1.6% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php. | |
| Modificada | Media (4.3) | 1.4% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php. | |
| Modificada | Media (5) | 1.6% | — | SUN ONE WEB Server | 25/2/2010 | 16/6/2026 | Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors. | |
| Modificada | Media (5) | 1.2% | — | SUN ONE WEB Server | 25/2/2010 | 16/6/2026 | Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors. | |
| Modificada | Media (4.3) | 0.89% | — | SUN ONE WEB Server | 5/2/2010 | 16/6/2026 | Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level… | |
| Modificada | Media (4.3) | 1.1% | — | SUN ONE WEB Server | 5/2/2010 | 16/6/2026 | Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format="… | |
| Modificada | Baja (2.6) | 1.1% | — | SUN ONE WEB Server | 5/2/2010 | 16/6/2026 | Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a… |