Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 2.0% | — | SUN Java System Application ServerSUN ONE Application Server | 26/6/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Sun ONE Application Server v7 anterior a actualización v9, Java System Application Server v7 2004Q2 anterior a actualización v5, y Java System Application Server Enterprise Edition v8.1 2005 Q1 permite a atacantes remotos inyecatr código HTML o web a… | |
| Modificada | Media (6.8) | 3.4% | — | SUN Java System Application ServerSUN Java System WEB ServerSUN ONE Application ServerSUN ONE WEB Server | 20/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Platform and Standard Edition Update 6 and earlier, and Java System Application Server 7 2004Q2 Standard and Enterprise Edition Update 2 and earlier, allows… | |
| Modificada | Alta (10) | 2.8% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | IBM WebSphere Application Server 5.0.2 and earlier, 5.1.1 and earlier, and 6.0.2 up to 6.0.2.7 records user credentials in plaintext in addNode.log, which allows attackers to gain privileges. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the 500 Internal Server Error page on the SOAP port (8880/tcp) in IBM WebSphere Application Server 5.0.2 and earlier, 5.1.x before 5.1.1.12, and 6.0.2 up to 6.0.2.7, allows remote attackers to inject arbitrary web script or HTML via the URI, which is contained in a… | |
| Modificada | Alta (7.5) | 2.5% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | IBM WebSphere Application Server 5.0.2 (or any earlier cumulative fix) and 5.1.1 (or any earlier cumulative fix) allows EJB access on Solaris systems via a crafted LTPA token. | |
| Modificada | Media (5) | 1.7% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | Unspecified vulnerability in WebSphere 5.1.1 (or any earlier cumulative fix) Common Configuration Mode + CommonArchive and J2EE Models might allow attackers to obtain sensitive information via the trace. | |
| Modificada | Alta (10) | 1.9% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and remote attack vectors related to "HTTP request handlers". | |
| Modificada | Media (6.4) | 2.6% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere Application Server 5.0.2 and earlier, and 5.1.1 and earlier, has unknown impact and attack vectors related to "Inserting certain script tags in urls [that] may allow unintended execution of scripts." | |
| Modificada | Alta (10) | 1.9% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere Application Server 6.0.2, 6.0.2.1, 6.0.2.3, 6.0.2.5, and 6.0.2.7 has unknown impact and attack vectors related to the "administrative console". | |
| Modificada | Alta (7.5) | 2.0% | — | IBM Websphere Application Server | 17/5/2006 | 16/6/2026 | WebSphere Application Server 5.0.2 (or any earlier cumulative fix) stores admin and LDAP passwords in plaintext in the FFDC logs when a login to WebSphere fails, which allows attackers to gain privileges. | |
| Modificada | Alta (7.5) | 2.7% | — | IBM Websphere Application Server | 12/5/2006 | 16/6/2026 | IBM WebSphere Application Server 6.0.2 before FixPack 3 allows remote attackers to bypass authentication for the Welcome Page via a request to the default context root. | |
| Modificada | Alta (10) | 4.6% | — | Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+8 | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. | |
| Modificada | Media (5) | 1.6% | — | IBM Websphere Application Server | 5/4/2006 | 16/6/2026 | IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header. | |
| Modificada | Media (5) | 2.6% | — | Orionserver Orion Application Server | 24/3/2006 | 16/6/2026 | Orion Application Server before 2.0.7, when running on Windows, allows remote attackers to obtain the source code of JSP files via (1) . (dot) and (2) space characters in the extension of a URL. | |
| Modificada | Media (6.4) | 1.4% | — | IBM Websphere Application Server | 9/3/2006 | 16/6/2026 | Unspecified vulnerability in IBM WebSphere 5.0.2.10 through 5.0.2.15 and 5.1.1.4 through 5.1.1.9 allows remote attackers to obtain sensitive information via unknown attack vectors, which causes JSP source code to be revealed. | |
| Modificada | Media (6.4) | 2.7% | 💥 Exploit | SAP WEB Application Server | 7/3/2006 | 16/6/2026 | SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers. | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | Oracle Application ServerOracle10g | 8/2/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Oracle 10g Release 1 en versiones anteriores a CPU de Enero de 2006 permiten a atacantes remotos ejecutar comandos SQL arbitrarios a través de parámetros múltiples en funciones (1) ATTACH_JOB, (2) HAS_PRIVS y (3) OPEN_JOB en el paquete SYS.KUPV$FT; y funciones (4)… | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+8 | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. | |
| Modificada | Alta (7.5) | 6.8% | — | Oracle Application ServerOracle Http Server | 26/1/2006 | 16/6/2026 | Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the… | |
| Modificada | Alta (10) | 6.5% | — | Oracle Application ServerOracle E-business Suite | 18/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Application Server | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01. | |
| Modificada | Alta (10) | 6.5% | — | Oracle Application ServerOracle Collaboration SuiteOracle Database Server | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects & Convert Tablespace component. | |
| Modificada | Alta (10) | 5.9% | — | Oracle Application ServerOracle E-business Suite | 18/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component. | |
| Modificada | Alta (10) | 6.0% | — | Oracle Application ServerOracle Collaboration SuiteOracle Database Server | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol… | |
| Modificada | Alta (10) | 29% | 💥 Exploit | Oracle Application ServerOracle Database Server | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02. |