Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

374 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)11%💥 ExploitIntervations Navicopa WEB Server28/3/200716/6/2026
Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112.
ModificadaMedia (6)0.91%—SUN Java System WEB Server20/3/200716/6/2026
Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors.
ModificadaAlta (7.5)2.5%—SUN Java System WEB Server16/3/200716/6/2026
Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application.
ModificadaAlta (7.5)82%💥 ExploitApache Tomcat JK WEB Server Connector4/3/200716/6/2026
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker…
ModificadaAlta (7.8)3.8%💥 ExploitNickolas Grigoriadis Mini WEB Server14/2/200716/6/2026
Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI.
ModificadaAlta (9.3)1.9%—Jportal WEB Server13/2/200716/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php.
ModificadaAlta (7.5)1.3%—Grigoriadis Mini WEB Server26/1/200716/6/2026
Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors.
ModificadaMedia (6.8)1.2%—Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+1526/1/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps.
ModificadaMedia (6.8)3.9%💥 ExploitSUN Iplanet WEB Server12/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)2.8%💥 ExploitHttp Explorer WEB Server27/12/200616/6/2026
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the URI.
ModificadaMedia (6.8)3.6%—SUN Java System Application ServerSUN Java System WEB Proxy ServerSUN Java System WEB ServerSUN ONE Application Server4/12/200616/6/2026
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified…
ModificadaMedia (6.8)1.7%💥 ExploitBiba Software Seleniumserver WEB Server26/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)7.2%💥 ExploitEssentia WEB Server10/11/200616/6/2026
Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)6.4%💥 ExploitEFS Software EFS WEB Server4/11/200616/6/2026
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream.
ModificadaMedia (4.3)1.2%—EFS Software EFS WEB Server4/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) author, (2) content, or (3) title parameters when posting a forum thread. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (4)2.1%—SUN Java System WEB ServerSUN ONE Application Server3/11/200616/6/2026
Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details…
ModificadaAlta (7.5)67%💥 ExploitIntervations Navicopa WEB Server3/10/200616/6/2026
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)2.6%💥 ExploitComscripts WEB Server Creator13/9/200616/6/2026
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
ModificadaMedia (5.1)2.2%💥 ExploitEFS Software Easy Address Book WEB Server9/9/200616/6/2026
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.
ModificadaMedia (4)2.2%—SUN Java System Application ServerSUN Java System WEB Server28/7/200616/6/2026
Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.
ModificadaMedia (5)1.8%—Eitsop MY WEB Server2/6/200616/6/2026
Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request. NOTE: CVE analysis suggests that this is a different product, and therefore a different vulnerability, than CVE-2002-1897.
ModificadaMedia (6.8)3.4%—SUN Java System Application ServerSUN Java System WEB ServerSUN ONE Application ServerSUN ONE WEB Server20/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows…
ModificadaMedia (5)1.5%—Northern Solutions Xeneo WEB Server9/5/200616/6/2026
Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.
ModificadaAlta (7.5)3.7%—SWS Simple WEB Server1/5/200616/6/2026
Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request.
ModificadaAlta (7.5)3.3%—SWS Simple WEB Server1/5/200616/6/2026
Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function call.