Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.45%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the…
AplazadaBaja (2.1)0.46%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has…
AplazadaCrítica (9.8)1.1%—Hiawatha-webserver HiawathaAI31/7/202631/8/2026
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
AnalizadaMedia (6.5)0.38%—Hiawatha.leisink Hiawatha Webserver26/1/202617/6/2026
A Double Free in XSLT `show_index` has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to corrupt data which may lead to arbitrary code execution.
AnalizadaBaja (3.3)0.16%—Hiawatha-webserver Hiawatha26/1/202617/6/2026
Tomahawk auth timing attack due to usage of `strcmp` has been identified in Hiawatha webserver version 11.7 which allows a local attacker to access the management client.
AnalizadaMedia (5.3)0.48%—Hiawatha-webserver Hiawatha26/1/202617/6/2026
Improper header parsing may lead to request smuggling has been identified in Hiawatha webserver version 11.7 which allows an unauthenticated attacker to access restricted resources managed by Hiawatha webserver.
AplazadaAlta (8.8)0.88%—CompactwebserverAI26/1/202617/6/2026
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication. Hence, it is possible to retrieve all files stored on the file…
AplazadaAlta (8.7)2.9%—Geovision GeowebserverAI16/1/202617/6/2026
GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and…
AnalizadaAlta (8.7)0.57%—Sylkat-tools Awebserver15/1/202617/6/2026
AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.
AnalizadaAlta (7.1)0.95%—Easyphp Webserver18/12/202517/6/2026
EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET requests with encoded directory traversal sequences like /..%5c..%5c to read system files such as…
AnalizadaCrítica (9.3)6.4%—Easyphp Webserver18/12/202517/6/2026
EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to /index.php?zone=settings with crafted app_service_control…
AplazadaMedia (6.9)0.36%—EBM Technologies Uniweb Solipacs WebserverAI13/10/202517/6/2026
Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain user group names.
AplazadaMedia (6.9)0.36%—EBM Technologies UniwebAIEBM Technologies Solipacs WebserverAI13/10/202517/6/2026
Uniweb/SoliPACS WebServer developed by EBM Technologies has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to access a specific page to obtain information such as account names and IP addresses.
AplazadaAlta (7.5)0.94%—Dagster-webserverAI7/7/202517/6/2026
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').
AplazadaCrítica (9.3)0.58%—Vertiv WebserverAI21/5/202517/6/2026
Affected Vertiv products do not properly protect webserver functions that could allow an attacker to bypass authentication.
AnalizadaMedia (6.9)0.51%—Markparticle Webserver21/4/202517/6/2026
A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part of the file code/http/httprequest.cpp of the component Login. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (6.9)0.51%—Markparticle Webserver21/4/202517/6/2026
A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file code/http/httprequest.cpp of the component Registration. The manipulation of the argument username/password leads to sql injection. The attack may be launched…
AnalizadaMedia (6.9)0.70%—Markparticle Webserver21/4/202517/6/2026
A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulnerability is the function Buffer::HasWritten of the file code/buffer/buffer.cpp. The manipulation of the argument writePos_ leads to buffer overflow. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.77%—Qinguoyi Tinywebserver4/4/202517/6/2026
A vulnerability has been found in qinguoyi TinyWebServer up to 1.0 and classified as critical. This vulnerability affects unknown code of the file http/http_conn.cpp. The manipulation of the argument m_url_real leads to improper authentication. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.53%—Qinguoyi Tinywebserver4/4/202517/6/2026
A vulnerability, which was classified as critical, was found in qinguoyi TinyWebServer up to 1.0. This affects an unknown part of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.80%—Qinguoyi Tinywebserver4/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in qinguoyi TinyWebServer up to 1.0. Affected by this issue is some unknown functionality of the file /http/http_conn.cpp. The manipulation of the argument name/password leads to stack-based buffer overflow. The attack may be launched remotely. The…
AnalizadaMedia (6.5)0.76%—Easyphp Webserver14/11/202417/6/2026
Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings…
AplazadaAlta (7.5)0.77%—Inotec Sicherheitstechnik Webserver Cps220/64AI4/4/202417/6/2026
INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as with the /cgi-bin/display?file=/etc/passwd URI.
AnalizadaAlta (8.8)0.77%—Ebmtech Uniweb/solipacs Webserver15/2/202417/6/2026
EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even leverage the dbo…
ModificadaAlta (7.5)0.71%—Chendotjs Lotos Webserver5/2/202417/6/2026
Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.