Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

658 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.70%—BEA Weblogic Server31/12/200316/6/2026
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that was intended for another user.
ModificadaBaja (2.1)0.21%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
ModificadaMedia (5)1.2%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server proxy plugin for BEA Weblogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (proxy plugin crash) via a malformed URL.
ModificadaBaja (2.1)0.36%—BEA Weblogic Server31/12/200316/6/2026
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.
ModificadaMedia (5)1.2%—BEA Weblogic Server31/12/200316/6/2026
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.
ModificadaMedia (5)1.4%—BEA Weblogic Server31/12/200316/6/2026
BEA Weblogic Express and Server 8.0 through 8.1 SP 1, when using a foreign Java Message Service (JMS) provider, echoes the password for the foreign provider to the console and stores it in cleartext in config.xml, which could allow attackers to obtain the password.
ModificadaMedia (5)2.4%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server and WebLogic Express 6.1, 7.0, and 8.1, with RMI and anonymous admin lookup enabled, allows remote attackers to obtain configuration information by accessing MBeanHome via the Java Naming and Directory Interface (JNDI).
ModificadaBaja (2.1)0.40%—BEA Weblogic Server31/12/200316/6/2026
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
ModificadaBaja (2.1)0.21%—BEA Weblogic Server31/12/200316/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.
ModificadaMedia (5)8.0%💥 ExploitBEA TuxedoBEA Weblogic Server1/12/200316/6/2026
La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos determinar la existencia de ficheros fuera de la raíz web mediante rutas modificadas en el argumento INFILE.
ModificadaMedia (5)1.8%—BEA TuxedoBEA Weblogic Server1/12/200316/6/2026
La consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante argumentos de nombre de ruta que contienen nombres de dispositivos de MS-DOS como CON o AUX.
ModificadaMedia (4.3)3.8%💥 ExploitBEA Weblogic Server1/12/200316/6/2026
Vulnerabilidad de scripts en sitios cruzados en Interactive.jsp de BEA WebLogic 8.1 y anteriores permite a atacantes remotos inyectar script web malicioso mediante el parámetro person.
ModificadaMedia (4.3)1.5%—BEA TuxedoBEA Weblogic Server1/12/200316/6/2026
Vulnerabilidad de scripts en sitios cruzados en la consola de adminstración de BEA Tuxedo 8.1 y anteriores permite a atacantes remotos inyectar script web arbitrario mediante una argumento INFILE.
ModificadaMedia (6.8)1.3%—BEA Liquid DataBEA Weblogic IntegrationBEA Weblogic Server20/10/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other…
ModificadaAlta (10)2.0%—BEA Weblogic Server27/8/200316/6/2026
BEA WebLogic Server y Express, cuando usa NodeManager para iniciar servidores, provee al usuarios Operadores con privilegios para sobreesctibir nombres de usuario y contraseñas, lo que puede permitir a Operadores ganar privielgios de Admin.
ModificadaAlta (7.5)2.5%💥 ExploitFactosystem Weblog2/4/200316/6/2026
Múltiples vulnerabilidades de inyección de SQL en FactoSystem CMS permite a atacantes remotos realizar actividades no autorizadas sobre la base de datos mediante el parámetro authornumber en author.asp el parámetro discussblurbid en discuss.asp el parámetro name en holdcomment.asp, y el parámetro email e…
ModificadaAlta (7.5)3.9%—BEA Weblogic Server24/3/200316/6/2026
BEA Weblogic Server y Express 6.0 a 7.0 no restringe adecuadamente el acceso a ciertos servlets internos que llevan a cabo funciones administrativas, lo que permite a atacantes remotos leer ficheros arbitrarios o ejecutar código arbitrario.
ModificadaMedia (4.6)0.38%—BEA Weblogic Server18/3/200316/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.
ModificadaAlta (7.5)1.3%—BEA Weblogic IntegrationBEA Weblogic Server31/12/200216/6/2026
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role…
ModificadaBaja (2.6)1.4%—BEA Weblogic Server31/12/200216/6/2026
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
ModificadaAlta (7.5)2.4%—BEA Weblogic Server31/12/200216/6/2026
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to…
ModificadaBaja (2.6)1.4%—BEA Weblogic Server4/10/200216/6/2026
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
ModificadaMedia (5)7.1%💥 ExploitBEA Weblogic Server25/3/200216/6/2026
El Servidor 6.1 Weblogic de BEA Sistemas, permite a atacantes que remotos causar una negación de servicio vía una serie de peticiones a archivos .JSP que contengan un nombre de dispositivo de MS-DOS.
ModificadaAlta (7.5)1.8%—Jason Hines Phpweblog16/2/200116/6/2026
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.
ModificadaAlta (10)78%💥 ExploitBEA Weblogic Server12/2/200116/6/2026
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.