Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
528 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.5% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAXWS Web Services Stack. | |
| Modificada | Alta (8.8) | 5.7% | — | Oracle Weblogic Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to JavaServer Faces. | |
| Modificada | Crítica (9.8) | 20% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3510. | |
| Modificada | Crítica (9.8) | 91% | 💥 Exploit | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586. | |
| Modificada | Crítica (9.8) | 8.9% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0 and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container. | |
| Modificada | Media (5.3) | 4.2% | — | Oracle Weblogic Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-5488. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality and integrity via vectors related to Console. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0675. | |
| Modificada | Media (5.4) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6 allows remote attackers to affect confidentiality and integrity via vectors related to Console. | |
| Modificada | Baja (3.7) | 2.1% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components. | |
| Modificada | Media (6.1) | 1.9% | — | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Console, a different vulnerability than CVE-2016-0700. | |
| Modificada | Crítica (9.8) | 63% | 💥 PoC | Oracle Weblogic Server | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0574. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-0577. | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Java Messaging Service. | |
| Modificada | Alta (7.5) | 2.6% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Coherence Container. | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Oracle Virtual Desktop InfrastructureOracle Storagetek Tape Analytics SW ToolOracle Weblogic Server | 18/11/2015 | 17/6/2026 | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the… | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Fusion MiddlewareOracle Weblogic Server | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container. | |
| Modificada | Media (6.4) | 6.5% | 💥 Exploit | BEA Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 13/7/2010 | 16/6/2026 | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS. | |
| Modificada | Alta (10) | 4.8% | — | Oracle Weblogic Server | 14/4/2010 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5) | 6.4% | — | IBM Websphere Application ServerMono Project MonoOracle Application ServerOracle BEA Product Suite+1 | 14/7/2009 | 16/6/2026 | The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3,… | |
| Modificada | Alta (10) | 84% | 💥 Exploit | BEA Weblogic ServerBEA Systems Apache Connector IN Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 22/7/2008 | 16/6/2026 | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. | |
| Modificada | Media (5) | 2.1% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 3.1% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.3) | 0.38% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 and 9.2 MP1 has unknown impact and local attack vectors. |