Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3206▲ 632 respecto a la semana anterior
Críticas / altas1515▲ 119 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—SWS Simple WEB Server31/12/200216/6/2026
Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution.
ModificadaAlta (7.8)1.1%—Mysimplenews31/12/200216/6/2026
MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.
ModificadaAlta (7.5)2.7%💥 ExploitMysimplenews31/12/200216/6/2026
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html.
ModificadaAlta (7.5)6.1%💥 ExploitIndependent Solution Simple Site SearcherIndependent Solution Super Site Searcher31/12/200216/6/2026
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.
ModificadaMedia (5)18%—SWS Simple WEB Server31/12/200216/6/2026
Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request.
ModificadaMedia (5)3.2%💥 ExploitSWS Simple WEB Server31/12/200216/6/2026
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline.
ModificadaAlta (10)3.0%—Springer Verlag Berlin Heidelberg Simple Wais31/12/200216/6/2026
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.
ModificadaAlta (7.5)7.1%💥 ExploitPeter Sandvik Simple WEB Server12/11/200216/6/2026
Peter Sandvik's Simple Web Server 0.5.1 y anteriores permite a atacantes remotos evitar las restricciones de acceso de ficheros mediante una petición HTTP con múltiples caracteres / (barra) como: http://www.example.com///file/
ModificadaAlta (7.5)3.3%—Analogx Simpleserver Shout4/10/200216/6/2026
Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001.
ModificadaAlta (7.5)6.5%💥 ExploitAnalogx Simpleserver WWW4/10/200216/6/2026
Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.
ModificadaMedia (5)1.5%—Arsc Really Simple Chat12/8/200216/6/2026
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.
ModificadaAlta (7.2)1.4%💥 ExploitRichard Gooch Simpleinit12/8/200216/6/2026
simpleinit on Linux systems does not close a read/write FIFO file descriptor before creating a child process, which allows the child process to cause simpleinit to execute arbitrary programs with root privileges.
ModificadaMedia (5)3.3%💥 ExploitAnalogx Simpleserver WWW2/7/200116/6/2026
AnalogX SimpleServer:WWW 1.08 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.
ModificadaMedia (5)3.5%—Dattaraj RAO Simple Server3/5/200116/6/2026
Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaAlta (10)5.4%💥 ExploitLeif M. Wright Simplestmail.cgi12/2/200116/6/2026
simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.
ModificadaAlta (10)13%💥 ExploitLeif M. Wright Simplestguest.cgi12/2/200116/6/2026
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.
ModificadaMedia (5)7.9%💥 ExploitAnalogx Simpleserver WWW26/7/200016/6/2026
AnalogX SimpleServer:WWW 1.06 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack that uses the %2E URL encoding for the dots.
ModificadaAlta (7.5)2.6%💥 ExploitAnalogx Simpleserver WWW15/6/200016/6/2026
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.
ModificadaMedia (5)7.3%💥 ExploitAnalogx Simpleserver WWW25/3/200016/6/2026
AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request to cgi-bin.
ModificadaAlta (7.5)9.4%💥 ExploitAnalogx Simpleserver WWW31/12/199916/6/2026
Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET request.