Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 31% | 💥 Exploit | Microsoft Internet Information Server | 11/2/1999 | 16/6/2026 | FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter. | |
| Modificada | Alta (10) | 5.1% | — | Microsoft Internet Information Server | 9/2/1999 | 16/6/2026 | By default, IIS 4.0 has a virtual directory /IISADMPWD which contains files that can be used as proxies for brute force password attacks, or to identify valid users on the system. | |
| Modificada | Media (5) | 11% | — | Microsoft Internet Information Server | 27/1/1999 | 16/6/2026 | IIS ASP caching problem releases sensitive information when two virtual servers share the same physical directory. | |
| Modificada | Alta (7.5) | 18% | — | Microsoft Internet Information Server | 27/1/1999 | 16/6/2026 | A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | |
| Modificada | Alta (7.8) | 49% | — | Microsoft Internet Information Server | 26/1/1999 | 16/6/2026 | The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 26/1/1999 | 16/6/2026 | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Information Server | 24/1/1999 | 16/6/2026 | Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command. | |
| Modificada | Alta (10) | 24% | — | Microsoft Internet Information Server | 14/1/1999 | 16/6/2026 | Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands. | |
| Modificada | Baja (2.1) | 25% | 💥 Exploit | Microsoft Internet Information Server | 14/1/1999 | 16/6/2026 | When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password. | |
| Modificada | Media (5) | 25% | 💥 Exploit | Microsoft Internet Information Server | 1/1/1999 | 16/6/2026 | IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | |
| Modificada | Alta (10) | 7.6% | — | Microsoft Internet Information ServicesAI | 1/1/1999 | 16/6/2026 | IIS has the #exec function enabled for Server Side Include (SSI) files. | |
| Modificada | Media (5) | 7.6% | — | C2net Stonghold WEB ServerHP Open Market Secure WebserverMicrosoft Exchange ServerMicrosoft Internet Information Server+9 | 26/6/1998 | 16/6/2026 | Information from SSL-encrypted sessions via PKCS #1. | |
| Modificada | Media (5) | 65% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Windows NT | 1/6/1998 | 16/6/2026 | In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. | |
| Modificada | Alta (7) | 19% | — | Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Personal WEB ServerNetscape Enterprise Server+1 | 6/2/1998 | 16/6/2026 | Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names. | |
| Modificada | Media (6.4) | 53% | 💥 Exploit | Microsoft Internet Information Server | 1/9/1997 | 16/6/2026 | IIS newdsn.exe CGI script allows remote users to overwrite files. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/6/1997 | 16/6/2026 | Denial of service in IIS using long URLs. | |
| Modificada | Alta (7.5) | 8.0% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/1/1997 | 16/6/2026 | IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Microsoft Internet Information Services | 25/2/1996 | 16/6/2026 | IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |