Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.2% | — | SUN Java System Application ServerSUN Java System WEB Server | 9/5/2008 | 16/6/2026 | Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Silver-forge Neptune WEB Server | 11/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page. | |
| Modificada | Media (4.3) | 2.2% | — | SUN Java System WEB Proxy ServerSUN Java System WEB Server | 28/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System WEB Proxy ServerSUN Java System WEB Server | 28/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System WEB Proxy ServerSUN Java System WEB Server | 28/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System WEB Proxy ServerSUN Java System WEB Server | 28/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204. | |
| Modificada | Media (4) | 7.1% | 💥 Exploit | Real Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server | 12/12/2007 | 16/6/2026 | Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Real Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server | 12/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page. | |
| Modificada | Media (5.5) | 6.0% | 💥 Exploit | Real Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server | 12/12/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot… | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Real Time Logic Barracudadrive WEB ServerReal Time Logic Barracudadrive WEB Server Home Server | 12/12/2007 | 16/6/2026 | BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1) + (plus), (2) . (dot), or (3) %80 and similar characters to the file name in the URL. | |
| Modificada | Media (5) | 0.78% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+10 | 5/11/2007 | 16/6/2026 | Hitachi Web Server 01-00 through 03-00-01, as used by certain Cosminexus products, does not properly validate SSL client certificates, which might allow remote attackers to spoof authentication via a client certificate with a forged signature. | |
| Modificada | Media (4.3) | 1.1% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+10 | 5/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page. | |
| Modificada | Media (5) | 41% | 💥 Exploit | Litespeed Technologies Litespeed WEB Server | 23/10/2007 | 16/6/2026 | LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection." | |
| Modificada | Alta (9.3) | 6.6% | — | ER Mapper Image WEB Server ECW Jpeg 2000 Plug-in | 10/9/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Earth Resource Mapping NCSView ActiveX control before 3.4.0.242 in NCSView.dll, as distributed in ER Mapper ECW JPEG 2000 Plug-in before 8.1, allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.5) | 2.0% | — | Teamspeak WEB Server | 25/8/2007 | 16/6/2026 | The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3)… | |
| Modificada | Media (4.3) | 1.3% | — | Teamspeak WEB Server | 25/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html. | |
| Modificada | Alta (7.5) | 2.5% | — | SUN Java System WEB Server | 7/8/2007 | 16/6/2026 | CRLF injection vulnerability in the redirect feature in Sun Java System Web Server 6.1 and 7.0 before 20070802, when the redirect Server Application Function (SAF) uses the url-prefix parameter and escape is disabled, or an Error directive uses the url-prefix parameter in obj.conf, allows remote attackers to inject… | |
| Modificada | Alta (7.8) | 8.1% | 💥 Exploit | Teamspeak WEB Server | 24/7/2007 | 16/6/2026 | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534. | |
| Modificada | Alta (9.3) | 2.3% | — | SUN Java System Application ServerSUN Java System WEB Server | 11/7/2007 | 16/6/2026 | Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute an arbitrary Java method via a crafted stylesheet, a related issue to CVE-2007-3716. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Oracle Application ServerOracle Rapid Install WEB Server | 3/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | KEY Focus KF WEB Server | 26/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.wkf in KeyFocus (KF) web server 3.1.0 allows remote attackers to inject arbitrary web script or HTML via the opsubmenu parameter. | |
| Modificada | Alta (7.8) | 14% | — | IBM Lotus Domino WEB Server | 6/6/2007 | 16/6/2026 | Unspecified vulnerability in the Lotus Domino Web Server 6.0, 6.5.x before 6.5.6, and 7.0.x before 7.0.3 allows remote attackers to cause a denial of service (daemon crash) via requests for URLs that reference certain files. | |
| Modificada | Media (5) | 13% | — | Apache Tomcat JK WEB Server Connector | 25/5/2007 | 16/6/2026 | mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory… | |
| Modificada | Media (5) | 2.2% | — | Pi3web WEB Server | 1/5/2007 | 16/6/2026 | Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally reported as a crash, but the vendor states that the impact is a "clean" exit in which "the server I/O loop finishes and the process exits normally." | |
| Modificada | Alta (7.8) | 3.2% | — | Intervations Navicopa WEB Server | 27/4/2007 | 16/6/2026 | Unspecified vulnerability in InterVations NaviCOPA Web Server 2.01 20070323 allows remote attackers to cause a denial of service (daemon crash) via crafted HTTP requests, as demonstrated by long requests containing '\A' characters, probably a different issue than CVE-2006-5112 and CVE-2007-1733. NOTE: the provenance… |