Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 296 respecto a la semana anterior
Críticas / altas1350▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | — | OpenldapRedhat Jboss Core ServicesRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB Server+3 | 28/5/2021 | 17/6/2026 | A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability. | |
| Analizada | Crítica (9.1) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. | |
| Analizada | Crítica (9.8) | 1.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. | |
| Analizada | Alta (7.5) | 1.0% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. | |
| Analizada | Crítica (9.8) | 1.4% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. | |
| Analizada | Crítica (9.8) | 1.3% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. | |
| Modificada | Crítica (9.8) | 8.5% | — | Zerof WEB Server | 13/4/2021 | 17/6/2026 | ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. | |
| Modificada | Alta (7.5) | 1.8% | — | Aprelium Abyss WEB Server X1 | 8/4/2021 | 17/6/2026 | An issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bounds read that crashes the application. | |
| Modificada | Crítica (9.8) | 2.9% | — | Cellinx NVT WEB Server | 6/11/2020 | 17/6/2026 | Cellinx NVT Web Server 5.0.0.014b.test 2019-09-05 allows a remote user to run commands as root via SetFileContent.cgi because authentication is on the client side. | |
| Modificada | Alta (7.5) | 82% | — | Oracle Iplanet WEB Server | 10/5/2020 | 17/6/2026 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to… | |
| Modificada | Media (4.8) | 1.3% | — | Oracle Iplanet WEB Server | 10/5/2020 | 17/6/2026 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com… | |
| Modificada | Alta (7.5) | 4.3% | — | Pablosoftwaresolutions Quick 'N Easy WEB Server | 28/2/2020 | 17/6/2026 | The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free. | |
| Modificada | Media (5.9) | 0.60% | — | Fujitsu Gp7000f FirmwareFujitsu Primepower FirmwareFujitsu GPS FirmwareFujitsu Sparc Enterprise M3000 Firmware+36 | 7/2/2020 | 17/6/2026 | The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions,… | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Jboss BrmsRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss Operations Network+2 | 23/1/2020 | 16/6/2026 | EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation. | |
| Modificada | Media (5.3) | 1.3% | — | Amcrest WEB Server | 18/1/2020 | 17/6/2026 | An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (ability to see… | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Alta (8.1) | 1.5% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has tmp file race condition flaws | |
| Modificada | Crítica (9.8) | 2.4% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 15/12/2019 | 17/6/2026 | eDeploy has RCE via cPickle deserialization of untrusted data | |
| Modificada | Baja (3.3) | 0.32% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise WEB Server | 6/12/2019 | 16/6/2026 | An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies | |
| Modificada | Crítica (9.8) | 2.8% | — | Redhat EdeployRedhat Jboss Enterprise WEB Server | 21/11/2019 | 17/6/2026 | eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data | |
| Modificada | Media (4.3) | 0.46% | — | Redhat KeycloakRedhat Jboss Enterprise WEB Server | 13/11/2019 | 17/6/2026 | JBoss KeyCloak is vulnerable to soft token deletion via CSRF | |
| Modificada | Crítica (9.8) | 89% | — | Apache StrutsRedhat Jboss Enterprise WEB Server | 1/11/2019 | 16/6/2026 | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. | |
| Modificada | Alta (7.5) | 1.3% | — | Cherokee-project Cherokee WEB Server | 22/7/2019 | 17/6/2026 | Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack vector is: Overwrite argv[0] to an insane length with execl. The fixed version is: There's no fix yet. | |
| Modificada | Alta (8.8) | 2.7% | — | Cesanta Mongoose Embedded WEB Server Library | 10/6/2019 | 17/6/2026 | Use-after-free vulnerability in the mg_cgi_ev_handler function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.13 and earlier allows a denial of service (application crash) or remote code execution. |