Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 27/12/2011 | 16/6/2026 | GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | |
| Modificada | Media (4.3) | 4.8% | — | Goahead Webserver | 3/11/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary web script or HTML via (1) the group parameter to goform/AddGroup, related to addgroup.asp; (2) the url parameter to goform/AddAccessLimit, related to addlimit.asp; or the (3) user (aka User ID) or… | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-2001-0385. | |
| Modificada | Media (5) | 1.6% | — | Goahead WebserverGoahead Software Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an invalid URL, related to the websSafeUrl function. | |
| Modificada | Alta (7.5) | 1.2% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | Unspecified vulnerability in GoAhead WebServer before 2.1.4 allows remote attackers to cause "incorrect behavior" via unknown "malicious code," related to incorrect use of the socketInputBuffered function by sockGen.c. | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server. | |
| Modificada | Media (5) | 1.1% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request that contains a negative integer in the Content-Length header. | |
| Modificada | Media (5) | 1.6% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | webs.c in GoAhead WebServer before 2.1.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP POST request that contains a Content-Length header but no body data. | |
| Modificada | Media (5) | 1.3% | — | Goahead Webserver | 6/2/2009 | 16/6/2026 | The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content via "an extra slash in a URL," a different vulnerability than CVE-2002-1603. | |
| Modificada | Media (5) | 2.6% | — | Goahead Software Fs4104-aw DeviceGoahead Software Goahead Webserver | 4/3/2008 | 16/6/2026 | goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the typepassword field, which allows remote attackers to obtain this password by reading the HTML source, a different vulnerability than CVE-2002-1603. | |
| Modificada | Alta (7.5) | 5.8% | — | Goahead Software Goahead Webserver | 31/12/2002 | 16/6/2026 | Buffer overflow in GoAhead WebServer 2.1 allows remote attackers to execute arbitrary code via a long HTTP GET request with a large number of subdirectories. | |
| Modificada | Media (5) | 3.5% | — | Goahead Software Goahead WebserverOrange Software Orange WEB ServerMontavista Software Hard HAT Linux | 23/7/2002 | 16/6/2026 | Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. | |
| Modificada | Alta (7.5) | 8.3% | — | Goahead Software Goahead Webserver | 23/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web users via script in a URL that generates a "404 not found" message, which does not quote the script. | |
| Modificada | Media (5) | 14% | — | Goahead Software Goahead Webserver | 13/2/2002 | 16/6/2026 | GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated with a /, \, %2f (encoded /), %20 (encoded space), or %00 (encoded null) character, which returns the ASP source code unparsed. | |
| Modificada | Media (5) | 8.4% | — | Goahead Software Goahead Webserver | 2/7/2001 | 16/6/2026 | GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory. | |
| Modificada | Media (5) | 3.6% | — | Goahead Software Goahead Webserver | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request. |