Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

1234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.3%—Oracle Application ServerOracle8i3/5/200116/6/2026
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.
ModificadaMedia (5)3.3%💥 ExploitIBM Http ServerIBM Websphere Application Server13/3/200116/6/2026
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
ModificadaAlta (7.5)1.9%—Oracle Application Server31/12/200023/9/2026
Vulnerabilidad de inyección SQL en mod_sql en Oracle Internet Application Server (IAS) 3.0.7 y anteriores permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de la cadena de consulta de la URL.
ModificadaMedia (5)4.8%—Oracle Application Server31/12/200023/9/2026
Las configuraciones predeterminadas de (1) el oyente del puerto y (2) modplsql en Oracle Internet Application Server (IAS) 3.0.7 y anteriores permiten a atacantes remotos ver información privilegiada de la base de datos a través de solicitudes HTTP para archivos Database Access Descriptor (DAD).
ModificadaAlta (10)6.4%💥 ExploitIBM Websphere Application Server14/11/200016/6/2026
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header.
ModificadaMedia (5)8.0%💥 ExploitIBM Websphere Application Server24/7/200016/6/2026
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string.
ModificadaAlta (7.5)3.1%—IBM Websphere Application Server8/6/200016/6/2026
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
ModificadaAlta (7.5)27%💥 ExploitOracle Application Server15/3/200016/6/2026
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
ModificadaAlta (7.2)0.34%—IBM Websphere Application Server2/12/199916/6/2026
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.
Orbitaley — Vulnerabilidades