Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 11% | 💥 Exploit | Intervations Navicopa WEB Server | 28/3/2007 | 16/6/2026 | Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112. | |
| Modificada | Media (6) | 0.91% | — | SUN Java System WEB Server | 20/3/2007 | 16/6/2026 | Sun Java System Web Server 6.1 before 20070314 allows remote authenticated users with revoked client certificates to bypass the Certificate Revocation List (CRL) authorization control and access secure web server instances running under an account different from that used for the admin server via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.5% | — | SUN Java System WEB Server | 16/3/2007 | 16/6/2026 | Unspecified vulnerability in Sun Java System Web Server 6.0 and 6.1 before 20070315 allows remote attackers to "gain unauthorized access to data", possibly involving a sample application. | |
| Modificada | Alta (7.5) | 82% | 💥 Exploit | Apache Tomcat JK WEB Server Connector | 4/3/2007 | 16/6/2026 | Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker… | |
| Modificada | Alta (7.8) | 3.8% | 💥 Exploit | Nickolas Grigoriadis Mini WEB Server | 14/2/2007 | 16/6/2026 | Directory traversal vulnerability in Nickolas Grigoriadis Mini Web server (MiniWebsvr) 0.0.6 allows remote attackers to list the directory immediately above the web root via a ..%00 sequence in the URI. | |
| Modificada | Alta (9.3) | 1.9% | — | Jportal WEB Server | 13/2/2007 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to admin/admin.adm.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Grigoriadis Mini WEB Server | 26/1/2007 | 16/6/2026 | Multiple buffer overflows in Nickolas Grigoriadis Mini Web server (MiniWebsvr) before 0.05 have unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+15 | 26/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | SUN Iplanet WEB Server | 12/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Http Explorer WEB Server | 27/12/2006 | 16/6/2026 | Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the URI. | |
| Modificada | Media (6.8) | 3.6% | — | SUN Java System Application ServerSUN Java System WEB Proxy ServerSUN Java System WEB ServerSUN ONE Application Server | 4/12/2006 | 16/6/2026 | HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified… | |
| Modificada | Media (6.8) | 1.7% | 💥 Exploit | Biba Software Seleniumserver WEB Server | 26/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SeleniumServer Web Server 1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Essentia WEB Server | 10/11/2006 | 16/6/2026 | Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 6.4% | 💥 Exploit | EFS Software EFS WEB Server | 4/11/2006 | 16/6/2026 | Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream. | |
| Modificada | Media (4.3) | 1.2% | — | EFS Software EFS WEB Server | 4/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) author, (2) content, or (3) title parameters when posting a forum thread. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (4) | 2.1% | — | SUN Java System WEB ServerSUN ONE Application Server | 3/11/2006 | 16/6/2026 | Unspecified vulnerability in the Network Security Services (NSS) in Sun Java System Web Server 6.0 before SP 10 and ONE Application Server 7 before Update 3, when SSLv2 is enabled, allows remote authenticated users to cause a denial of service (application crash) via unspecified vectors. NOTE: due to lack of details… | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | Intervations Navicopa WEB Server | 3/10/2006 | 16/6/2026 | Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Comscripts WEB Server Creator | 13/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter. | |
| Modificada | Media (5.1) | 2.2% | 💥 Exploit | EFS Software Easy Address Book WEB Server | 9/9/2006 | 16/6/2026 | Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string. | |
| Modificada | Media (4) | 2.2% | — | SUN Java System Application ServerSUN Java System WEB Server | 28/7/2006 | 16/6/2026 | Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI. | |
| Modificada | Media (5) | 1.8% | — | Eitsop MY WEB Server | 2/6/2006 | 16/6/2026 | Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request. NOTE: CVE analysis suggests that this is a different product, and therefore a different vulnerability, than CVE-2002-1897. | |
| Modificada | Media (6.8) | 3.4% | — | SUN Java System Application ServerSUN Java System WEB ServerSUN ONE Application ServerSUN ONE WEB Server | 20/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows… | |
| Modificada | Media (5) | 1.5% | — | Northern Solutions Xeneo WEB Server | 9/5/2006 | 16/6/2026 | Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension. | |
| Modificada | Alta (7.5) | 3.7% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request. | |
| Modificada | Alta (7.5) | 3.3% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function call. |