Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.93% | 💥 Exploit | Aquacms Aqua CMS | 17/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Aquagardensoft Mysql-lists | 27/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.5% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Collaboration | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Foundation | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (5) | 1.6% | — | BEA Aqualogic Interaction | 1/12/2007 | 16/6/2026 | The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | BEA Aqualogic Interaction | 1/12/2007 | 16/6/2026 | portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter. | |
| Modificada | Media (6.8) | 2.0% | — | Aqualung | 2/3/2007 | 16/6/2026 | Buffer overflow in the meta_read_flac function in meta_decoder.c for Aqualung 0.9beta5 and earlier, and CVS 0.193.2 and earlier, allows user-assisted attackers to execute arbitrary code via a long Vorbis comment in a Free Lossless Audio Codec (FLAC) file. | |
| Modificada | Media (4.6) | 0.33% | — | BEA Aqualogic Enterprise Security | 23/1/2007 | 16/6/2026 | BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity level of audit events when the system load is high, which might make it easier for attackers to avoid detection. | |
| Modificada | Media (6.5) | 1.3% | — | BEA Aqualogic Service BUS | 23/1/2007 | 16/6/2026 | Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when using Active Directory LDAP for authentication, allows remote authenticated users to access the server even after the account has been disabled. | |
| Modificada | Alta (7.5) | 1.5% | — | BEA Aqualogic Service BUS | 23/1/2007 | 16/6/2026 | BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, which might allow remote attackers to bypass authorization policies and route requests to back-end services or conduct other unauthorized activities. |