Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.5% | — | Miniweb Http ServerAI | 1/8/2025 | 16/6/2026 | An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, followed by a .mof… | |
| Modificada | Alta (7.5) | 2.7% | — | Miniweb Http Server Project Miniweb Http Server | 21/12/2020 | 17/6/2026 | MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request. | |
| Modificada | Media (4.3) | 1.2% | — | Intesync Miniweb | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | |
| Modificada | Alta (7.5) | 0.91% | — | Intesync Miniweb | 4/1/2010 | 16/6/2026 | SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php. | |
| Modificada | Media (4.3) | 1.2% | — | Intesync Miniweb | 25/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO. | |
| Modificada | Alta (7.5) | 0.91% | — | Intesync Miniweb | 25/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter. | |
| Modificada | Alta (7.5) | 0.98% | — | Miniweb2 Miniweb | 2/4/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action. | |
| Modificada | Alta (7.5) | 0.98% | — | Miniweb2 Blog Writer | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in the blogwriter module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter to index.php. | |
| Modificada | Media (5) | 2.8% | — | Miniweb Http Server | 17/1/2008 | 16/6/2026 | Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI. | |
| Modificada | Alta (7.5) | 5.4% | — | Miniweb Http Server | 17/1/2008 | 16/6/2026 | Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Media (5) | 2.8% | — | Miniweb Http Server | 11/6/2007 | 16/6/2026 | http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header. |