Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.3% | — | Oracle Application ServerOracle8i | 3/5/2001 | 16/6/2026 | Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | IBM Http ServerIBM Websphere Application Server | 13/3/2001 | 16/6/2026 | Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error. | |
| Modificada | Alta (7.5) | 1.9% | — | Oracle Application Server | 31/12/2000 | 23/9/2026 | Vulnerabilidad de inyección SQL en mod_sql en Oracle Internet Application Server (IAS) 3.0.7 y anteriores permite a atacantes remotos ejecutar comandos SQL arbitrarios a través de la cadena de consulta de la URL. | |
| Modificada | Media (5) | 4.8% | — | Oracle Application Server | 31/12/2000 | 23/9/2026 | Las configuraciones predeterminadas de (1) el oyente del puerto y (2) modplsql en Oracle Internet Application Server (IAS) 3.0.7 y anteriores permiten a atacantes remotos ver información privilegiada de la base de datos a través de solicitudes HTTP para archivos Database Access Descriptor (DAD). | |
| Modificada | Alta (10) | 6.4% | 💥 Exploit | IBM Websphere Application Server | 14/11/2000 | 16/6/2026 | Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via a long Host: request header. | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | IBM Websphere Application Server | 24/7/2000 | 16/6/2026 | IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default InvokerServlet using a URL which contains the "/servlet/file" string. | |
| Modificada | Alta (7.5) | 3.1% | — | IBM Websphere Application Server | 8/6/2000 | 16/6/2026 | IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Oracle Application Server | 15/3/2000 | 16/6/2026 | Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'. | |
| Modificada | Alta (7.2) | 0.34% | — | IBM Websphere Application Server | 2/12/1999 | 16/6/2026 | IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin. |