Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | Oracle Weblogic Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Coherence Container. | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Oracle Virtual Desktop InfrastructureOracle Storagetek Tape Analytics SW ToolOracle Weblogic Server | 18/11/2015 | 17/6/2026 | The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands via a crafted serialized Java object in T3 protocol traffic to TCP port 7001, related to oracle_common/modules/com.bea.core.apache.commons.collections.jar. NOTE: the… | |
| Modificada | Media (4.3) | 1.2% | — | Maianscriptworld Maian Weblog | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, or (3) subject parameter in a contact action to index.php. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Events ManagerNetweblogic Events Manager PRO | 13/5/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) scope parameter to index.php; (2) user_name, (3) dbem_phone, (4) user_email, or (5)… | |
| Modificada | Media (6.8) | 0.97% | — | Netweblogic Login With Ajax | 10/5/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings. | |
| Modificada | Media (4.3) | 1.2% | — | Fleugel Myu-sFleugel PHP Weblog System Mania | 6/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FLUGELz netmania myu-s and PHP WeblogSystem allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 22/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php. | |
| Modificada | Alta (7.5) | 0.90% | 💥 Exploit | Aspindir Xweblog | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Aspindir Xweblog | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the makale_id parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Fusion MiddlewareOracle Weblogic Server | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container. | |
| Modificada | Media (6.4) | 6.5% | 💥 Exploit | BEA Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 13/7/2010 | 16/6/2026 | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS. | |
| Modificada | Alta (10) | 4.8% | — | Oracle Weblogic Server | 14/4/2010 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (4.3) | 0.87% | — | Alentum Weblog Expert | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue. | |
| Modificada | Media (5) | 6.4% | — | IBM Websphere Application ServerMono Project MonoOracle Application ServerOracle BEA Product Suite+1 | 14/7/2009 | 16/6/2026 | The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3,… | |
| Modificada | Media (5) | 1.2% | — | Factosystem Weblog | 21/1/2009 | 16/6/2026 | Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5.1) | 1.4% | — | Oracle Weblogic Workshop | 14/10/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite WLW 8.1SP5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to "some NetUI pageflows." | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Maian Weblog | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary weblog_cookie cookie. | |
| Modificada | Alta (10) | 84% | 💥 Exploit | BEA Weblogic ServerBEA Systems Apache Connector IN Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 22/7/2008 | 16/6/2026 | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. | |
| Modificada | Media (5.1) | 1.7% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors related to UDDI Explorer. | |
| Modificada | Media (4.3) | 0.38% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 and 9.2 MP1 has unknown impact and local attack vectors. | |
| Modificada | Alta (7.5) | 3.1% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Media (5) | 2.1% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.6) | 2.1% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2 MP1 has unknown impact and remote authenticated attack vectors. | |
| Modificada | Media (4.4) | 0.41% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2, 9.1, 9.0, and 8.1 SP6 has unknown impact and local attack vectors. |