Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3206▲ 632 respecto a la semana anterior
Críticas / altas1515▲ 119 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Infovista Portalse | 23/2/2006 | 16/6/2026 | InfoVista PortalSE 2.0 Build 20087 on Solaris 8 allows remote attackers to obtain sensitive information by specifying a nonexistent server in the server field, which reveals the path in an error message. | |
| Modificada | Media (5) | 1.6% | — | Infovista Portalse | 23/2/2006 | 16/6/2026 | Unspecified vulnerability in InfoVista PortalSE 2.0 Build 20087 on Solaris 8 without the IV00038969 hotfix allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+8 | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dragoran Portal Module | 2/2/2006 | 16/6/2026 | SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.9% | — | Oracle Weblogic Portal | 25/1/2006 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Portal 8.1 SP3 through SP5, when using Web Services Remote Portlets (WSRP), allows remote attackers to access restricted web resources via crafted URLs. | |
| Modificada | Media (5) | 2.5% | — | Oracle Weblogic Portal | 25/1/2006 | 16/6/2026 | BEA WebLogic Portal 8.1 through SP4 allows remote attackers to obtain the source for a deployment descriptor file via unknown vectors. | |
| Modificada | Alta (7.5) | 4.4% | — | Oracle Weblogic Portal | 25/1/2006 | 16/6/2026 | BEA WebLogic Portal 8.1 through SP3 stores the password for the RDBMS Authentication provider in cleartext in the config.xml file, which allows attackers to gain privileges. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Powerportal | 22/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2. | |
| Modificada | Alta (10) | 4.5% | — | Oracle Peoplesoft Enterprise Portal | 18/1/2006 | 16/6/2026 | Unspecified vulnerability in Oracle PeopleSoft Enterprise Portal 8.4 Bundle 15, 8.8 Bundle 10, and 8.9 Bundle 2 has unspecified impact and attack vectors, as identified by Oracle Vuln# PSE01. | |
| Modificada | Media (4.3) | 1.1% | — | Codeworx Technologies Dcp-portal | 16/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3 through 6.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the day parameter in calendar.php and (2) the input form in search.php. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Phanatic Softwares Chimera WEB Portal | 9/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phanatic Softwares Chimera WEB Portal | 9/1/2006 | 16/6/2026 | SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.2% | 💥 Exploit | Triggertg Tclanportal | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Tangora Portal CMS | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tangora Portal CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter in a search page, as demonstrated using (1) page1631.aspx and (2) page496.aspx. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Iatek Portalapp | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in PortalApp 3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the ret_page parameter. | |
| Modificada | Alta (9) | 1.8% | — | Metadot Portal Server | 21/12/2005 | 16/6/2026 | Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liferay Portal Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in downloads/portal_ent in Liferay Portal Enterprise 3.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) _77_struts_action, (2) p_p_mode, and (3) p_p_state parameters. | |
| Modificada | Alta (7.8) | 2.0% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the… | |
| Modificada | Media (4.3) | 1.4% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule… | |
| Modificada | Alta (7.5) | 3.1% | — | Codeworx Technologies Dcp-portal | 14/12/2005 | 16/6/2026 | Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_member_id, year, agid, day, day_s, hour, minute, month, month_s,… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Arab Portal | 14/12/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en link.php en Arab Portal System 2 Beta 2 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el (1) PHPSESSID (ID de sesión) o (2) REQUEST_URI (cadena de consulta) | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Internet Scout Scout Portal Toolkit | 13/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the ss parameter in SPT--QuickSearch.php; (2) ParentId parameter in SPT--BrowseResources.php; (3) the ResourceId parameter in SPT--FullRecord.php;… | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Internet Scout Scout Portal ToolkitInternet Scout Project Scout Portal Toolkit | 13/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en Scout Portal Toolkit (SPT) 1.3.1 y anteriores permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1)ParentId parameter en SPT--BrowseResources.php, el parámetro (2) ResourceId en SPT--FullRecord.php, el parámetro (3) ResourceOffset… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Duware Duportal PROAI | 11/12/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en password.asp de DUWare DUportal Pro 3.4.3 permite a atacantes remotos inyectar 'script' web o HTML de su elección mediante el parámetro result. |