Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.0% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools." | |
| Modificada | Media (5) | 2.6% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown) via modified cookies. | |
| Modificada | Alta (7.5) | 2.2% | — | BEA Weblogic ServerOracle Weblogic Portal | 24/5/2005 | 16/6/2026 | BEA WebLogic Server and WebLogic Express 8.1 through Service Pack 3 and 7.0 through Service Pack 5 does not properly handle when a security provider throws an exception, which may cause WebLogic to use incorrect identity for the thread, or to fail to audit security exceptions. | |
| Modificada | Media (5) | 1.2% | — | Jgs-xa Jgs-portal | 17/5/2005 | 16/6/2026 | JGS-XA JGS-Portal 3.0.2 and earlier allows remote attackers to obtain the full server path via direct requests to (1) jgs_portal_ref.php, (2) jgs_portal_land.php, (3) jgs_portal_log.php, (4) jgs_portal_global_sponsor.php, (5) jgs_portal_global.php, (6) jgs_portal_system.php, (7) jgs_portal_views.php; or multiple files… | |
| Modificada | Media (4.3) | 1.4% | — | Jgs-xa Jgs-portal | 17/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.php, (3) year parameter to jgs_portal_beitraggraf.php, (4) tag… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Jgs-xa Jgs-portal | 17/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to… | |
| Modificada | Alta (7.5) | 2.0% | — | Maxwebportal | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to… | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Jgs-xa Jgs-portal | 11/5/2005 | 16/6/2026 | SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Maxwebportal | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | HP Openview Radia Management Portal | 3/5/2005 | 16/6/2026 | Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Maxwebportal | 3/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5) article_rate.asp, (6) dl_rate.asp, (7)… | |
| Modificada | Alta (7.5) | 1.3% | — | Maxwebportal | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in the Update_Events function in events_functions.asp in MaxWebPortal 1.33 and earlier allows remote attackers to execute arbitrary SQL commands via the EVENT_ID parameter, as demonstrated using events.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Iatek Portalapp | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Storeportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Duware Duportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2) iData parameter to detail.asp or inc_rating.asp, (3) iCat parameter to detail.asp or type.asp, (4) DAT_PARENT parameter… | |
| Modificada | Media (4.3) | 1.4% | — | Iatek Portalapp | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in content.asp in Iatek PortalApp allow remote attackers to inject arbitrary web script or HTML via the (1) contenttype or (2) keywords parameter. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Vortex Portal | 2/5/2005 | 16/6/2026 | PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Codeworx Technologies Dcp-portal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Duware Duportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result.asp, cat.asp, or detail.asp (3) the iCat parameter to cat.asp… | |
| Modificada | Media (5) | 1.2% | — | Vortex Portal | 2/5/2005 | 16/6/2026 | content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message. | |
| Modificada | Media (4.3) | 1.2% | — | Maxwebportal | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in links_add_form.asp for MaxWebPortal 1.33 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URL in a banner URL. | |
| Modificada | Media (4.3) | 20% | — | Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services | 2/5/2005 | 16/6/2026 | Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache. | |
| Modificada | Alta (7.5) | 4.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+11 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Jportal WEB PortalAI | 12/4/2005 | 16/6/2026 | SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter. | |
| Modificada | Media (5) | 1.6% | — | Vignette Application Portal | 27/1/2005 | 16/6/2026 | The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote attackers to gain sensitive information, such as server and OS version, and conduct unauthorized activities via an HTTP request to /diag. |