Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3206▲ 632 respecto a la semana anterior
Críticas / altas1515▲ 119 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 11/5/2000 | 16/6/2026 | ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" vulnerability. | |
| Modificada | Media (5) | 29% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 10/5/2000 | 16/6/2026 | Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability. | |
| Modificada | Media (5) | 44% | 💥 Exploit | Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Internet Information Services | 6/5/2000 | 16/6/2026 | The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path. | |
| Modificada | Alta (7.5) | 19% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/4/2000 | 16/6/2026 | IIS 4.0 y 5.0 permite a atacantes remotos provocar una denegación de servicio enviando muchas URLs con un largo número de caracteres de escape, también conocida como la Vulnerabilidad "Myriad Escaped Characters". | |
| Modificada | Media (5) | 80% | 💥 Exploit | Microsoft Commercial Internet SystemMicrosoft Internet Information ServerMicrosoft Internet Information ServicesMicrosoft Proxy Server+2 | 30/3/2000 | 16/6/2026 | IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Microsoft Windows Media Services | 23/2/2000 | 16/6/2026 | The Windows Media server allows remote attackers to cause a denial of service via a series of client handshake packets that are sent in an improper sequence, aka the "Misordered Windows Media Services Handshake" vulnerability. | |
| Modificada | Media (5) | 28% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 11/1/2000 | 16/6/2026 | IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions. | |
| Modificada | Media (5) | 40% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 31/12/1999 | 16/6/2026 | IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Microsoft MSN Setup Bulletin Board Services | 24/9/1999 | 16/6/2026 | Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 19/2/1999 | 16/6/2026 | In IIS and other web servers, an attacker can attack commands as SYSTEM if the server is running as SYSTEM and loading an ISAPI extension. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 26/1/1999 | 16/6/2026 | In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe). | |
| Modificada | Alta (10) | 7.6% | — | Microsoft Internet Information ServicesAI | 1/1/1999 | 16/6/2026 | IIS has the #exec function enabled for Server Side Include (SSI) files. | |
| Modificada | Media (5) | 13% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/6/1997 | 16/6/2026 | Denial of service in IIS using long URLs. | |
| Modificada | Alta (7.5) | 8.0% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 1/1/1997 | 16/6/2026 | IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Microsoft Internet Information Services | 25/2/1996 | 16/6/2026 | IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files. |