Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | — | Broadcom Cleverpath Portal | 10/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the portal login page in Computer Associates CleverPath 4.7 allows remote attackers to execute Javascript via unknown vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cars Portal | 7/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Web4future Portal Solutions | 6/12/2005 | 16/6/2026 | Directory traversal vulnerability in arhiva.php in Web4Future Portal Solutions News Portal allows remote attackers to read arbitrary files via the dir parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Web4future Portal Solutions | 6/12/2005 | 16/6/2026 | SQL injection vulnerability in comentarii.php in Web4Future Portal Solutions News Portal allows remote attackers to execute arbitrary SQL commands via the idp parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Jportal WEB Portal | 6/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php. | |
| Modificada | Alta (7.5) | 3.2% | — | Codeworx Technologies Dcp-portal | 30/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3) the year parameter in calendar.php, and the (4) cid parameter… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | JportalAI | 24/9/2005 | 16/6/2026 | SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php. | |
| Modificada | Alta (7.5) | 1.7% | — | Savewebportal | 24/8/2005 | 16/6/2026 | Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php. | |
| Modificada | Alta (7.5) | 1.7% | — | Savewebportal | 24/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php. | |
| Modificada | Media (4.3) | 0.99% | — | Savewebportal | 24/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SaveWebPortal 3.4 allow remote attackers to inject arbitrary web script or HTML via a large number of parameters to (1) footer.php, (2) header.php, (3) menu_dx.php, or (4) menu_sx.php, or Javascript code in the (5) HTTP_REFERER (referer) or (6) HTTP_USER_AGENT… | |
| Modificada | Alta (7.5) | 1.5% | — | Savewebportal | 24/8/2005 | 16/6/2026 | SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via a direct request to admin/PhpMyExplorer/editerfichier.php, then editing the desired file to contain the PHP code, as demonstrated using header.php in the fichier parameter. NOTE: it is possible that this vulnerability stems from PhpMyExplorer,… | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Media (5) | 3.4% | — | Oracle Weblogic Portal | 23/8/2005 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Media (5) | 1.2% | — | Arab Portal | 10/8/2005 | 16/6/2026 | Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called. | |
| Modificada | Alta (10) | 3.2% | — | WPS WEB Portal SystemAI | 18/7/2005 | 16/6/2026 | wps_shop.cgi en WPS Web Portal System 0.7.0 permite que atacantes remotos ejecuten ordenes web de su elección mediante metacaracteres de 'shell' en la variable (1) "art" a (2) "cat". | |
| Modificada | Alta (7.5) | 1.3% | — | Duware Duportal PRO | 22/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUportal PRO 3.4.3 allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to default.asp, (2) iData parameter to detail.asp, (3) iMem parameter to members.asp, (4) iCat parameter to cat.asp, (5) offset parameter to… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Maxwebportal | 31/5/2005 | 16/6/2026 | SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | NET Portal Dynamic System | 29/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | NET Portal Dynamic System | 29/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sdv_infos.php, (4) the categories parameter to faq.php, (5) the… | |
| Modificada | Media (6.8) | 5.1% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, via the (1) j_username or (2) j_password parameters in the login… | |
| Modificada | Media (5) | 3.2% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping). | |
| Modificada | Media (5) | 2.6% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service. | |
| Modificada | Media (4.6) | 0.59% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password. |