Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Perception Liteserve31/12/200216/6/2026
Buffer overflow in HTTP server in LiteServe 2.0, 2.0.1 and 2.0.2 allows remote attackers to cause a denial of service (hang) via a large number of percent characters (%) in an HTTP GET request.
ModificadaMedia (5)6.7%💥 ExploitPerception Liteserve31/12/200216/6/2026
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP request with a trailing dot (".").
ModificadaMedia (4.3)1.2%—HNSHns-lite31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML.
ModificadaMedia (5)1.2%—Perception Liteserve31/12/200216/6/2026
Perception LiteServe 2.0 allows remote attackers to read password protected files via a leading "/./" in a URL.
ModificadaMedia (5)1.6%—Paul Kulchenko Soap Lite31/12/200216/6/2026
SOAP::Lite 0.50 through 0.52 allows remote attackers to load arbitrary Perl functions by suppling a non-existent function in a script using a SOAP::Lite module, which causes the AUTOLOAD subroutine to trigger.
ModificadaMedia (4.3)3.7%💥 ExploitPerception Liteserve31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web script via (1) a Host: header when DNS wildcards are supported or (2) the query string in a "dir" request to indexed folders.
ModificadaAlta (10)7.8%💥 ExploitGalacticomm Technologies WorldgroupGalacticomm Technologies Worldgroup Lite Personal Server25/6/200216/6/2026
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.
ModificadaAlta (7.5)5.1%💥 ExploitGalacticomm Technologies WorldgroupGalacticomm Technologies Worldgroup Lite Personal Server25/6/200216/6/2026
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.
ModificadaMedia (5)1.6%—Snapgear Lite+ Firewall18/6/200216/6/2026
Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options.
ModificadaMedia (5)1.6%—Snapgear Lite+ Firewall18/6/200216/6/2026
Snapgear Lite+ firewall 1.5.3 allows remote attackers to cause a denial of service (IPSEC crash) via a zero length packet to UDP port 500.
ModificadaMedia (5)1.9%—Snapgear Lite+ Firewall18/6/200216/6/2026
Snapgear Lite+ firewall 1.5.4 and 1.5.3 allows remote attackers to cause a denial of service (crash) via a large number of connections to (1) the HTTP web management port, or (2) the PPTP port.
ModificadaAlta (7.5)2.0%—Cmfperception Liteserve18/10/200116/6/2026
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.
ModificadaMedia (6.4)1.7%—Pop3lite2/9/200116/6/2026
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise…
ModificadaMedia (5)6.7%💥 ExploitSoft Lite Serverworx2/6/200116/6/2026
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.
ModificadaMedia (5)1.6%—CGI Script Center Subscribe ME Lite12/2/200116/6/2026
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.
ModificadaAlta (7.5)7.8%💥 ExploitCGI Script Center Subscribe ME Lite20/10/200016/6/2026
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.
ModificadaMedia (5.1)0.89%—Backweb Technologies Backweb Polite Agent Protocol1/1/199916/6/2026
A race condition in the BackWeb Polite Agent Protocol allows an attacker to spoof a BackWeb server.
ModificadaAlta (7.2)0.43%—Delix DLDCaldera Openlinux LiteDebian LinuxLST Power Linux+217/7/199716/6/2026
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
ModificadaAlta (7.2)0.35%—SCO Open DesktopSCO Open Desktop LiteSCO Openserver Enterprise SystemSCO Openserver Network System+130/11/199416/6/2026
Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.
ModificadaAlta (7.2)0.34%—SCO Open DesktopSCO Open Desktop LiteSCO Openserver Enterprise SystemSCO Openserver Network System+130/11/199416/6/2026
Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.
ModificadaAlta (7.2)0.35%—SCO Open DesktopSCO Open Desktop LiteSCO Openserver Enterprise SystemSCO Openserver Network System+130/11/199416/6/2026
Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.
ModificadaAlta (7.2)0.35%—SCO Open DesktopSCO Open Desktop LiteSCO Openserver Enterprise SystemSCO Openserver Network System+130/11/199416/6/2026
Unspecified vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.
ModificadaAlta (10)1.6%—SCO Open DesktopSCO Open Desktop LiteSCO OpenserverSCO Unix17/9/199316/6/2026
SCO UNIX System V/386 Release 3.2, and other SCO products, installs the home directories (1) /tmp for the dos user, and (2) /usr/tmp for the asg user, which allows other users to gain access to those accounts since /tmp and /usr/tmp are world-writable.