Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1625 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Dayfox Designs Dayfox Blog | 22/5/2006 | 16/6/2026 | Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient access control, which allows remote attackers to gain privileges. | |
| Modificada | Media (4) | 1.2% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | BEA WebLogic Server 8.1 up to SP4, 7.0 up to SP6, and 6.1 up to SP7 displays the internal IP address of the WebLogic server in the WebLogic Server Administration Console, which allows remote authenticated administrators to determine the address. | |
| Modificada | Media (4) | 1.2% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | The WebLogic Server Administration Console in BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 displays the domain name in the Console login form, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (4.9) | 0.35% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Server 9.1 and 9.0, 8.1 through SP5, 7.0 through SP6, and 6.1 through SP7 allows untrusted applications to obtain private server keys. | |
| Modificada | Alta (7.5) | 1.3% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | The HTTP handlers in BEA WebLogic Server 9.0, 8.1 up to SP5, 7.0 up to SP6, and 6.1 up to SP7 stores the username and password in cleartext in the WebLogic Server log when access to a web application or protected JWS fails, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 2.1% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | BEA WebLogic Server before 8.1 Service Pack 4 does not properly set the Quality of Service in certain circumstances, which prevents some transmissions from being encrypted via SSL, and allows remote attackers to more easily read potentially sensitive network traffic. | |
| Modificada | Alta (7.5) | 1.8% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | Unspecified vulnerability in the WebLogic Server Administration Console for BEA WebLogic Server 9.0 prevents the console from setting custom JDBC security policies correctly, which could allow attackers to bypass intended policies. | |
| Modificada | Media (5) | 1.4% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6, may send sensitive data over non-secure channels when using JTA transactions, which allows remote attackers to read potentially sensitive network traffic. | |
| Modificada | Baja (2.6) | 1.2% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | BEA WebLogic Server 8.1 up to SP4 and 7.0 up to SP6 allows remote attackers to obtain the source code of JSP pages during certain circumstances related to a "timing window" when a compilation error occurs, aka the "JSP showcode vulnerability." | |
| Modificada | Media (5) | 1.4% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | Multiple vulnerabilities in BEA WebLogic Server 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 leak sensitive information to remote attackers, including (1) DNS and IP addresses to address to T3 clients, (2) internal sensitive information using GetIORServlet, (3) certain "server details" in exceptions when… | |
| Modificada | Media (4.6) | 0.33% | — | BEA Weblogic Server | 19/5/2006 | 16/6/2026 | stopWebLogic.sh in BEA WebLogic Server 8.1 before Service Pack 4 and 7.0 before Service Pack 6 displays the administrator password to stdout when executed, which allows local users to obtain the password by viewing a local display. | |
| Modificada | Media (5.8) | 1.5% | — | Uapplication Ublog | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UBlog 1.6 Access Edition allows remote attackers to inject arbitrary web script or HTML via text fields when adding a blog entry. | |
| Modificada | Media (6.4) | 1.4% | — | Invision Power Services Invision Community Blog | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mywebland Mybloggie | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Bitdamaged Geoblog | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Alta (10) | 2.4% | — | Servous Sblog | 4/5/2006 | 16/6/2026 | SQL injection vulnerability in search.php in Servous sBLOG 0.7.2 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: this issue can be used to trigger path disclosure. In addition, it might be primary to vector 1 in CVE-2006-1135. | |
| Modificada | Media (6.4) | 1.6% | 💥 Exploit | Blog MOD | 1/5/2006 | 16/6/2026 | SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Michael Romedahl RI Blog | 25/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in RI Blog 1.1 allow remote attackers to execute arbitrary SQL command via the (1) username or (2) password fields. | |
| Modificada | Alta (7.5) | 1.5% | — | Paras Chopra Bloggage | 25/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in check_login.asp in Bloggage allow remote attackers to execute arbitrary SQL commands via the (1) acc_name and (2) password parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Ar-blog | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Baja (2.6) | 1.3% | — | DEV Neuron Blog | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters. | |
| Modificada | Alta (7.5) | 1.8% | — | JL Webworks Quickblogger | 14/4/2006 | 16/6/2026 | Directory traversal vulnerability in acc.php in QuickBlogger 1.4 allows remote attackers to read or include arbitrary local files via the request parameter. NOTE: this issue can also produce resultant XSS when the associated include statement fails. | |
| Modificada | Baja (2.6) | 1.2% | — | Michiel VAN Baak Mvblog | 12/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the backend in MvBlog before 1.6 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) body fields in a comment. | |
| Modificada | Alta (7.5) | 1.2% | — | Michiel VAN Baak Mvblog | 12/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MvBlog before 1.6 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5.1) | 1.6% | — | Wire Plastik Design Wpblog | 6/4/2006 | 16/6/2026 | SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. |