Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.2%—SUN Java System Application ServerSUN Java System WEB Server9/5/200816/6/2026
Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.
ModificadaMedia (4.3)1.5%💥 ExploitSilver-forge Neptune WEB Server11/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.
ModificadaMedia (4.3)2.2%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
ModificadaMedia (4.3)1.9%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.
ModificadaMedia (4)7.1%💥 ExploitReal Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server12/12/200716/6/2026
Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference.
ModificadaMedia (4.3)3.6%💥 ExploitReal Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server12/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.
ModificadaMedia (5.5)6.0%💥 ExploitReal Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server12/12/200716/6/2026
Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot…
ModificadaMedia (5)7.2%💥 ExploitReal Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server12/12/200716/6/2026
BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the URL.
ModificadaMedia (5)0.78%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+105/11/200716/6/2026
Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature.
ModificadaMedia (4.3)1.1%—Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+105/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page.
ModificadaMedia (5)41%💥 ExploitLitespeed Technologies Litespeed WEB Server23/10/200716/6/2026
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection."
ModificadaAlta (9.3)6.6%—ER Mapper Image WEB Server ECW Jpeg 2000 Plug-in10/9/200716/6/2026
Multiple stack-based buffer overflows in the Earth Resource Mapping NCSView ActiveX control before 3.4.0.242 in NCSView.dll, as distributed in ER Mapper ECW JPEG 2000 Plug-in before 8.1, allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (8.5)2.0%—Teamspeak WEB Server25/8/200716/6/2026
The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3)…
ModificadaMedia (4.3)1.3%—Teamspeak WEB Server25/8/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.
ModificadaAlta (7.5)2.5%—SUN Java System WEB Server7/8/200716/6/2026
CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject…
ModificadaAlta (7.8)8.1%💥 ExploitTeamspeak WEB Server24/7/200716/6/2026
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.
ModificadaAlta (9.3)2.3%—SUN Java System Application ServerSUN Java System WEB Server11/7/200716/6/2026
Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716.
ModificadaMedia (4.3)1.8%💥 ExploitOracle Application ServerOracle Rapid Install WEB Server3/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the…
ModificadaMedia (4.3)2.4%💥 ExploitKEY Focus KF WEB Server26/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter.
ModificadaAlta (7.8)14%—IBM Lotus Domino WEB Server6/6/200716/6/2026
Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files.
ModificadaMedia (5)13%—Apache Tomcat JK WEB Server Connector25/5/200716/6/2026
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory…
ModificadaMedia (5)2.2%—Pi3web WEB Server1/5/200716/6/2026
Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a "clean" exit in which "the server I/O loop finishes and the process exits normally."
ModificadaAlta (7.8)3.2%—Intervations Navicopa WEB Server27/4/200716/6/2026
Unspecified vulnerability in InterVations NaviCOPA Web Server 2.01 20070323 allows remote attackers to cause a denial of service (daemon crash) via crafted HTTP requests, as demonstrated by long requests containing '\A' characters, probably a different issue than CVE-2006-5112 and CVE-2007-1733. NOTE: the provenance…
Orbitaley — Vulnerabilidades