Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 13/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Login With Ajax plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Netweblogic Login With Ajax | 22/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login-with-ajax.php in the Login With Ajax (aka login-with-ajax) plugin before 3.0.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the callback parameter in a lostpassword action to wp-login.php. | |
| Modificada | Media (4.3) | 1.3% | — | Oracle Fusion MiddlewareOracle Weblogic Server | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container. | |
| Modificada | Media (6.4) | 6.5% | 💥 Exploit | BEA Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 13/7/2010 | 16/6/2026 | Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS. | |
| Modificada | Alta (10) | 4.8% | — | Oracle Weblogic Server | 14/4/2010 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5) | 6.4% | — | IBM Websphere Application ServerMono Project MonoOracle Application ServerOracle BEA Product Suite+1 | 14/7/2009 | 16/6/2026 | The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3,… | |
| Modificada | Media (5.1) | 1.4% | — | Oracle Weblogic Workshop | 14/10/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Workshop component in BEA Product Suite WLW 8.1SP5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to "some NetUI pageflows." | |
| Modificada | Alta (10) | 84% | 💥 Exploit | BEA Weblogic ServerBEA Systems Apache Connector IN Weblogic ServerBEA Systems Weblogic ServerOracle Weblogic Server | 22/7/2008 | 16/6/2026 | Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10.3 and earlier allows remote attackers to execute arbitrary code via a long HTTP version string, as demonstrated by a string after "POST /.jsp" in an HTTP request. | |
| Modificada | Media (5) | 1.8% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, and 9.0 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.6) | 2.1% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2 MP1 has unknown impact and remote authenticated attack vectors. | |
| Modificada | Media (5) | 2.1% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Media (4.3) | 0.38% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 and 9.2 MP1 has unknown impact and local attack vectors. | |
| Modificada | Media (4.4) | 0.41% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2, 9.1, 9.0, and 8.1 SP6 has unknown impact and local attack vectors. | |
| Modificada | Alta (7.5) | 3.1% | — | Oracle Weblogic Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors. | |
| Modificada | Media (5.1) | 1.7% | — | Oracle BEA Product SuiteOracle Weblogic Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors related to UDDI Explorer. | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Weblogic ExpressBEA Systems Weblogic Server | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL. | |
| Modificada | Media (6.4) | 2.2% | — | BEA Weblogic Server | 22/2/2008 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers. | |
| Modificada | Media (4.3) | 1.0% | — | BEA Weblogic Server | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page. | |
| Modificada | Media (6) | 10.0% | — | BEA Weblogic ServerBEA Systems Weblogic Express | 22/2/2008 | 16/6/2026 | Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors. | |
| Modificada | Alta (7.9) | 1.2% | — | BEA Weblogic Server | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions. | |
| Modificada | Media (4.9) | 0.80% | — | BEA Systems Weblogic Portal | 22/2/2008 | 16/6/2026 | BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions. | |
| Modificada | Media (4.3) | 1.0% | — | BEA Weblogic ServerBEA Systems Weblogic Server | 22/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694. | |
| Modificada | Media (5.8) | 1.1% | — | BEA Weblogic Server | 22/2/2008 | 16/6/2026 | The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues. | |
| Modificada | Alta (7.1) | 2.2% | — | BEA Weblogic ServerBEA Systems Weblogic Server | 22/2/2008 | 16/6/2026 | BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not. | |
| Modificada | Media (4.3) | 1.1% | — | BEA Weblogic ServerBEA Weblogic WorkshopBEA Systems Weblogic | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows. |