Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1781 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.5%—Dattaraj RAO Simple Server3/5/200116/6/2026
Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaAlta (10)71%💥 ExploitATT Winvnc3/5/200116/6/2026
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.
ModificadaAlta (7.6)51%💥 ExploitATT Winvnc3/5/200116/6/2026
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.
ModificadaAlta (10)15%💥 ExploitMatthew Smith MicqDebian LinuxRedhat Linux26/3/200116/6/2026
Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field.
ModificadaAlta (7.5)2.1%—ATT Winvnc23/1/200116/6/2026
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
ModificadaAlta (9)1.5%—ATT Winvnc9/1/200116/6/2026
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.
ModificadaAlta (7.5)7.7%💥 ExploitMatt Kruse Calendar Script16/5/200016/6/2026
The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters.
ModificadaMedia (5)2.7%💥 ExploitSeattle LAB Software Emurl15/5/200016/6/2026
The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account.
ModificadaAlta (7.5)1.6%—Matthew Redman Allmanage13/5/200016/6/2026
The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages.
ModificadaAlta (7.5)1.4%—Matthew Redman Allmanage13/5/200016/6/2026
The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.
ModificadaMedia (5)7.5%💥 ExploitMatt Wright Formmail10/5/200016/6/2026
Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter.
ModificadaAlta (7.2)0.82%💥 ExploitMatt Kimball AND Roger Wolff MTRTurbolinux3/3/200016/6/2026
The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges.
ModificadaMedia (5.1)1.6%—Chris Matthee Nftp31/12/199916/6/2026
Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string.
ModificadaMedia (5)1.4%—Matt Wright Formhandler.cgi16/11/199916/6/2026
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
ModificadaMedia (5)7.9%💥 ExploitMatt Wright Formhandler.cgi12/11/199916/6/2026
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.
ModificadaAlta (7.5)2.7%—Matts Whois9/11/199916/6/2026
Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.
ModificadaAlta (10)8.6%💥 ExploitMatt Wright Wwwboard16/9/199916/6/2026
WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers.
ModificadaAlta (7.5)1.1%—Matt Wright Wwwboard16/9/199916/6/2026
WWWBoard has a default username and default password.
ModificadaAlta (7.5)85%💥 ExploitApache Http ServerMatt Wright Guestbook13/9/199916/6/2026
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
ModificadaMedia (5)2.1%—Matt Wright Download.cgi9/9/199916/6/2026
Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
ModificadaAlta (7.5)1.1%—Seattle LAB Software Emurl28/7/199916/6/2026
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
ModificadaMedia (4.6)0.33%—Seattle LAB Software Slmail25/2/199916/6/2026
SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user.
ModificadaMedia (5)1.4%—Seattle LAB Software Slmail1/1/199916/6/2026
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.
ModificadaMedia (5)1.5%—Matt Wright Wwwboard3/9/199816/6/2026
wwwboard allows a remote attacker to delete message board articles via a malformed argument.
ModificadaAlta (7.5)2.0%—Seattle LAB Software Slmail9/7/199816/6/2026
Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.
Orbitaley — Vulnerabilidades