Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Apache StrutsIBM Storwize V3500 FirmwareIBM Storwize V5000 FirmwareIBM Storwize V7000 Firmware+5 | 11/3/2017 | 17/6/2026 | The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP… | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Oracle Weblogic Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0 and 12.2.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle… | |
| Modificada | Media (6.3) | 0.40% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components. | |
| Modificada | Crítica (9.8) | 5.1% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Crítica (9.8) | 5.1% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS-WebServices. | |
| Modificada | Media (5.3) | 3.5% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-3445. | |
| Modificada | Crítica (9.8) | 5.5% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXWS Web Services Stack. | |
| Modificada | Alta (8.8) | 5.7% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to JavaServer Faces. | |
| Modificada | Crítica (9.8) | 20% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510. | |
| Modificada | Crítica (9.8) | 91% | 💥 Exploit | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586. | |
| Modificada | Crítica (9.8) | 8.9% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0 and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container. | |
| Modificada | Media (5.3) | 4.2% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-5488. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality and integrity via vectors related to Console. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675. | |
| Modificada | Media (5.4) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 allows remote attackers to affect confidentiality and integrity via vectors related to Console. | |
| Modificada | Baja (3.7) | 2.1% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700. | |
| Modificada | Crítica (9.8) | 63% | 💥 PoC | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0574. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0577. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Java Messaging Service. | |
| Modificada | Alta (7.5) | 2.6% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Coherence Container. | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Oracle Virtual Desktop InfrastructureOracle Storagetek Tape Analytics SW ToolOracle Weblogic Server | 18/11/2015 | 17/6/2026 | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the… | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Events ManagerNetweblogic Events Manager PRO | 13/5/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5)… | |
| Modificada | Media (6.8) | 0.97% | — | Netweblogic Login With Ajax | 10/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. |