Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 1.7% | — | Simple WEB ServerAI | 8/8/2025 | 16/6/2026 | Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer overflow on the stack. This flaw allows remote… | |
| Modificada | Alta (7.5) | 3.7% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request. | |
| Modificada | Alta (7.5) | 3.3% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function call. | |
| Modificada | Alta (7.5) | 9.7% | — | Pmsoftware Simple WEB Server | 2/5/2005 | 16/6/2026 | Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Media (5) | 18% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request. | |
| Modificada | Media (5) | 3.2% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline. | |
| Modificada | Alta (7.5) | 2.7% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform actions on an uninitialized heap, leading to a denial of service and possibly code execution. | |
| Modificada | Media (5) | 1.6% | — | SWS Simple WEB Server | 31/12/2002 | 16/6/2026 | Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor exhaustion) via multiple requests for pages that do not exist. | |
| Modificada | Alta (7.5) | 7.1% | — | Peter Sandvik Simple WEB Server | 12/11/2002 | 16/6/2026 | Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/. |