Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
658 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.70% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user. | |
| Modificada | Baja (2.1) | 0.21% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access. | |
| Modificada | Media (5) | 1.2% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL. | |
| Modificada | Baja (2.1) | 0.36% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen. | |
| Modificada | Media (5) | 1.2% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap. | |
| Modificada | Media (5) | 1.4% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password. | |
| Modificada | Media (5) | 2.4% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI). | |
| Modificada | Baja (2.1) | 0.40% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords. | |
| Modificada | Baja (2.1) | 0.21% | — | BEA Weblogic Server | 31/12/2003 | 16/6/2026 | BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords. | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | BEA TuxedoBEA Weblogic Server | 1/12/2003 | 16/6/2026 | La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos determinar la existencia de ficheros fuera de la raíz web mediante rutas modificadas en el argumento INFILE. | |
| Modificada | Media (5) | 1.8% | — | BEA TuxedoBEA Weblogic Server | 1/12/2003 | 16/6/2026 | La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante argumentos de nombre de ruta que contienen nombres de dispositivos de MS-DOS como CON o AUX. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | BEA Weblogic Server | 1/12/2003 | 16/6/2026 | Vulnerabilidad de scripts en sitios cruzados en Interactive.jsp de BEA WebLogic 8.1 y anteriores permite a atacantes remotos inyectar script web malicioso mediante el parámetro person. | |
| Modificada | Media (4.3) | 1.5% | — | BEA TuxedoBEA Weblogic Server | 1/12/2003 | 16/6/2026 | Vulnerabilidad de scripts en sitios cruzados en la consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos inyectar script web arbitrario mediante una argumento INFILE. | |
| Modificada | Media (6.8) | 1.3% | — | BEA Liquid DataBEA Weblogic IntegrationBEA Weblogic Server | 20/10/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other… | |
| Modificada | Alta (10) | 2.0% | — | BEA Weblogic Server | 27/8/2003 | 16/6/2026 | BEA WebLogic Server y Express, cuando usa NodeManager para iniciar servidores, provee al usuarios Operadores con privilegios para sobreesctibir nombres de usuario y contraseñas, lo que puede permitir a Operadores ganar privielgios de Admin. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Factosystem Weblog | 2/4/2003 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en FactoSystem CMS permite a atacantes remotos realizar actividades no autorizadas sobre la base de datos mediante el parámetro authornumber en author.asp el parámetro discussblurbid en discuss.asp el parámetro name en holdcomment.asp, y el parámetro email e… | |
| Modificada | Alta (7.5) | 3.9% | — | BEA Weblogic Server | 24/3/2003 | 16/6/2026 | BEA Weblogic Server y Express 6.0 a 7.0 no restringe adecuadamente el acceso a ciertos servlets internos que llevan a cabo funciones administrativas, lo que permite a atacantes remotos leer ficheros arbitrarios o ejecutar código arbitrario. | |
| Modificada | Media (4.6) | 0.38% | — | BEA Weblogic Server | 18/3/2003 | 16/6/2026 | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate. | |
| Modificada | Alta (7.5) | 1.3% | — | BEA Weblogic IntegrationBEA Weblogic Server | 31/12/2002 | 16/6/2026 | An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role… | |
| Modificada | Baja (2.6) | 1.4% | — | BEA Weblogic Server | 31/12/2002 | 16/6/2026 | BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users. | |
| Modificada | Alta (7.5) | 2.4% | — | BEA Weblogic Server | 31/12/2002 | 16/6/2026 | BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to… | |
| Modificada | Baja (2.6) | 1.4% | — | BEA Weblogic Server | 4/10/2002 | 16/6/2026 | Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | BEA Weblogic Server | 25/3/2002 | 16/6/2026 | El Servidor 6.1 Weblogic de BEA Sistemas, permite a atacantes que remotos causar una negación de servicio vía una serie de peticiones a archivos .JSP que contengan un nombre de dispositivo de MS-DOS. | |
| Modificada | Alta (7.5) | 1.8% | — | Jason Hines Phpweblog | 16/2/2001 | 16/6/2026 | common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog. | |
| Modificada | Alta (10) | 78% | 💥 Exploit | BEA Weblogic Server | 12/2/2001 | 16/6/2026 | Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string. |