Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1781 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.5% | — | Dattaraj RAO Simple Server | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | ATT Winvnc | 3/5/2001 | 16/6/2026 | Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0. | |
| Modificada | Alta (7.6) | 51% | 💥 Exploit | ATT Winvnc | 3/5/2001 | 16/6/2026 | Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Matthew Smith MicqDebian LinuxRedhat Linux | 26/3/2001 | 16/6/2026 | Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Description field. | |
| Modificada | Alta (7.5) | 2.1% | — | ATT Winvnc | 23/1/2001 | 16/6/2026 | WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users. | |
| Modificada | Alta (9) | 1.5% | — | ATT Winvnc | 9/1/2001 | 16/6/2026 | WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Matt Kruse Calendar Script | 16/5/2000 | 16/6/2026 | The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote attackers to execute arbitrary commands via shell metacharacters. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Seattle LAB Software Emurl | 15/5/2000 | 16/6/2026 | The EMURL web-based email account software encodes predictable identifiers in user session URLs, which allows a remote attacker to access a user's email account. | |
| Modificada | Alta (7.5) | 1.6% | — | Matthew Redman Allmanage | 13/5/2000 | 16/6/2026 | The allmanageup.pl file upload CGI script in the Allmanage Website administration software 2.6 can be called directly by remote attackers, which allows them to modify user accounts or web pages. | |
| Modificada | Alta (7.5) | 1.4% | — | Matthew Redman Allmanage | 13/5/2000 | 16/6/2026 | The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Matt Wright Formmail | 10/5/2000 | 16/6/2026 | Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | |
| Modificada | Alta (7.2) | 0.82% | 💥 Exploit | Matt Kimball AND Roger Wolff MTRTurbolinux | 3/3/2000 | 16/6/2026 | The mtr program only uses a seteuid call when attempting to drop privileges, which could allow local users to gain root privileges. | |
| Modificada | Media (5.1) | 1.6% | — | Chris Matthee Nftp | 31/12/1999 | 16/6/2026 | Buffer overflow in nftp FTP client version 1.40 allows remote malicious FTP servers to cause a denial of service, and possibly execute arbitrary commands, via a long response string. | |
| Modificada | Media (5) | 1.4% | — | Matt Wright Formhandler.cgi | 16/11/1999 | 16/6/2026 | Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Matt Wright Formhandler.cgi | 12/11/1999 | 16/6/2026 | Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template. | |
| Modificada | Alta (7.5) | 2.7% | — | Matts Whois | 9/11/1999 | 16/6/2026 | Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry. | |
| Modificada | Alta (10) | 8.6% | 💥 Exploit | Matt Wright Wwwboard | 16/9/1999 | 16/6/2026 | WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. | |
| Modificada | Alta (7.5) | 1.1% | — | Matt Wright Wwwboard | 16/9/1999 | 16/6/2026 | WWWBoard has a default username and default password. | |
| Modificada | Alta (7.5) | 85% | 💥 Exploit | Apache Http ServerMatt Wright Guestbook | 13/9/1999 | 16/6/2026 | guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". | |
| Modificada | Media (5) | 2.1% | — | Matt Wright Download.cgi | 9/9/1999 | 16/6/2026 | Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Seattle LAB Software Emurl | 28/7/1999 | 16/6/2026 | Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message. | |
| Modificada | Media (4.6) | 0.33% | — | Seattle LAB Software Slmail | 25/2/1999 | 16/6/2026 | SLMail 3.1 and 3.2 allows local users to access any file in the NTFS file system when the Remote Administration Service (RAS) is enabled by setting a user's Finger File to point to the target file, then running finger on the user. | |
| Modificada | Media (5) | 1.4% | — | Seattle LAB Software Slmail | 1/1/1999 | 16/6/2026 | Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access. | |
| Modificada | Media (5) | 1.5% | — | Matt Wright Wwwboard | 3/9/1998 | 16/6/2026 | wwwboard allows a remote attacker to delete message board articles via a malformed argument. | |
| Modificada | Alta (7.5) | 2.0% | — | Seattle LAB Software Slmail | 9/7/1998 | 16/6/2026 | Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line. |