Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.5%—BEA Weblogic Server31/12/200516/6/2026
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, in certain "heavy usage" scenarios, report incorrect severity levels for an audit event, which might allow attackers to perform unauthorized actions and avoid detection.
ModificadaMedia (5)1.1%—BEA Weblogic Server31/12/200516/6/2026
BEA WebLogic Server and WebLogic Express 8.1 and 7.0, during a migration across operating system platforms, do not warn the administrative user about platform differences in URLResource case sensitivity, which might cause local users to inadvertently lose protection of Web Application pages.
ModificadaMedia (5)1.2%—Foojan PHP Weblog30/8/200516/6/2026
Foojan PHP Weblog allows remote attackers to obtain sensitive information via (1) a direct request to /daylinks/index.php or (2) a negative value in the daylinkspage parameter to index.php, which reveal the path in an error message.
ModificadaMedia (4.3)1.8%💥 ExploitFoojan PHP Weblog30/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) index.php or (2) admin.php in Foojan PHP Weblog allow remote attackers to inject arbitrary web script or HTML via the Referer field in the HTTP header.
ModificadaMedia (5)3.4%—Oracle Weblogic Portal23/8/200516/6/2026
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.
ModificadaMedia (4.3)1.4%💥 ExploitApple Weblog ServerApple MAC OS X19/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (4.3)1.5%—BEA Weblogic Server5/7/200516/6/2026
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebLogic to incorrectly handle and forward the body of the…
ModificadaMedia (5)3.0%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."
ModificadaAlta (7.5)2.2%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions.
ModificadaMedia (4.6)0.59%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.
ModificadaMedia (5)2.6%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.
ModificadaMedia (5)3.2%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).
ModificadaMedia (6.8)5.1%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login…
ModificadaCrítica (9.8)2.1%—BEA Weblogic Server24/5/200516/6/2026
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly changed security constraints or role mappings.
ModificadaMedia (5)2.6%—BEA Weblogic ServerOracle Weblogic Portal24/5/200516/6/2026
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies.
ModificadaMedia (6.8)5.0%💥 ExploitBEA Weblogic Server3/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.
ModificadaMedia (5)2.0%—BEA Weblogic Server2/5/200516/6/2026
BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.
ModificadaMedia (4.6)8.1%💥 ExploitJason Hines Phpweblog7/3/200516/6/2026
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web server that contains the code.
ModificadaBaja (2.1)0.21%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.
ModificadaAlta (7.5)1.5%—BEA Weblogic ServerAIBEA Weblogic ExpressAI31/12/200416/6/2026
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.
ModificadaMedia (5)7.1%💥 ExploitKorweblog31/12/200416/6/2026
Directory traversal vulnerability in viewimg.php in KorWeblog 1.6.2-cvs and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the path parameter.
ModificadaMedia (5.3)2.9%—BEA Weblogic Server31/12/200416/6/2026
The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site…
ModificadaMedia (4.6)0.42%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and Express 8.1, SP1 and earlier, stores the administrator password in cleartext in config.xml, which allows local users to gain privileges.
ModificadaAlta (7.5)1.7%—Korweblog31/12/200416/6/2026
PHP remote file inclusion vulnerability in main.inc in KorWeblog 1.6.2-cvs and earlier allows remote attackers to execute arbitrary PHP code by modifying the G_PATH parameter to reference a URL on a remote web server that contains the code, as demonstrated in index.php when using .. (dot dot) sequences in the lng…
ModificadaMedia (5)1.8%—BEA Weblogic Server31/12/200416/6/2026
BEA WebLogic Server and WebLogic Express 8.1 through 8.1 SP2 allow remote attackers to cause a denial of service (network port consumption) via unknown actions in HTTPS sessions, which prevents the server from releasing the network port when the session ends.
Orbitaley — Vulnerabilidades