Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)5.1%—Oracle Application Server2/11/200516/6/2026
Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01.
ModificadaAlta (10)4.1%—Oracle 10G Enterprise Manager Database ControlOracle Enterprise Manager Application Server Control2/11/200516/6/2026
Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01.
ModificadaAlta (10)5.1%—Oracle Application Server2/11/200516/6/2026
Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14.
ModificadaAlta (10)5.1%—Oracle Application Server2/11/200516/6/2026
Unspecified vulnerability in the HTTP Server in Oracle Application Server 1.0 up to 9.0.2.3 has unknown impact and attack vectors, as identified by Oracle Vuln# AS04.
ModificadaAlta (10)2.9%—Oracle Database ServerAIOracle Application ServerAI2/11/200516/6/2026
Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08.
ModificadaAlta (10)5.1%—Oracle Application Server2/11/200516/6/2026
Unspecified vulnerability in Web Cache in Oracle Application Server 1.0 up to 9.0.4.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS13.
ModificadaAlta (10)5.6%—Oracle Application ServerOracle Database Server2/11/200516/6/2026
Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.
ModificadaAlta (10)5.6%—Oracle Application Server2/11/200516/6/2026
Unspecified vulnerability in SQL*ReportWriter in Oracle Application Server 9.0 up to 9.0.2.1 has unknown impact and attack vectors, as identified by Oracle Vuln# AS10.
ModificadaMedia (4.3)21%💥 ExploitOracle Application ServerOracle9i14/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
ModificadaBaja (2.6)6.5%—Hitachi Cosminexus Application ServerApache Tomcat6/10/200516/6/2026
The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body…
ModificadaMedia (4.3)0.95%—Orionserver Orion Application Server20/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
ModificadaMedia (4.3)1.5%—IBM Websphere Application Server5/7/200516/6/2026
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of…
ModificadaMedia (4.3)4.9%—Oracle Application Server5/7/200516/6/2026
Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and…
ModificadaAlta (7.5)3.2%—IBM Websphere Application Server3/6/200516/6/2026
Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code.
ModificadaMedia (4.6)38%—Oracle Application ServerOracle10g11/5/200516/6/2026
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
ModificadaAlta (7.5)3.2%—Oracle Application ServerOracle10gOracle9i11/5/200516/6/2026
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
ModificadaMedia (6.8)20%💥 ExploitOracle Application Server WEB Cache3/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.
ModificadaMedia (5)7.0%💥 ExploitOracle Application Server WEB Cache3/5/200516/6/2026
The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.
ModificadaAlta (7.5)31%💥 ExploitOracle Application Server3/5/200516/6/2026
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.
ModificadaMedia (5)8.6%💥 ExploitIBM Websphere Application Server2/5/200516/6/2026
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
ModificadaMedia (4.3)1.8%—SUN Java System Application Server2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaMedia (5)2.1%—IBM Websphere Application Server2/5/200516/6/2026
Vulnerabilidad desconocida en IBM Websphere Application Server 5.0, 5.1, y 6.0 cuando es ejecutado en Windows, permite a atacantes remotos obtener el código fuente de Java Server Pages (.jsp) mediante una URL alterada que hace que la página sea procesada por el fichero que sirve el servlet en lugar de por el motor JSP.
ModificadaMedia (5)2.6%—Oracle Application ServerOracle9i31/12/200416/6/2026
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
ModificadaMedia (5)1.6%—SUN Java System Application ServerSUN Java System WEB Server31/12/200416/6/2026
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate.
ModificadaAlta (7.5)23%—Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+631/12/200416/6/2026
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
Orbitaley — Vulnerabilidades