Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Plugin-planet Simple Download Counter | 9/9/2023 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'before' and 'after'. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.38% | — | Plugin-planet User Submitted Posts | 6/9/2023 | 17/6/2026 | The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [usp_gallery] shortcode in versions up to, and including, 20230811 due to insufficient input sanitization and output escaping on user supplied attributes like 'before'. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.42% | — | Plugin-planet User Submitted Posts | 15/8/2023 | 17/6/2026 | The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-content’ parameter in versions up to, and including, 20230809 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Crítica (9.8) | 0.84% | — | Cncf Crossplane | 27/7/2023 | 17/6/2026 | Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, Crossplane's image backend does not validate the byte contents of Crossplane packages. As such, Crossplane does not detect if an attacker has tampered with a Package. The… | |
| Modificada | Baja (2.7) | 0.62% | — | Cncf Crossplane | 27/7/2023 | 17/6/2026 | Crossplane is a framework for building cloud native control planes without needing to write code. In versions prior to 1.11.5, 1.12.3, and 1.13.0, a high-privileged user could create a Package referencing an arbitrarily large image containing that Crossplane would then parse, possibly resulting in exhausting all the… | |
| Modificada | Media (4.6) | 0.53% | — | Plane | 15/7/2023 | 17/6/2026 | Plane version 0.7.1-dev allows an attacker to change the avatar of his profile, which allows uploading files with HTML extension that interprets both HTML and JavaScript. | |
| Modificada | Alta (7.5) | 0.66% | — | Plane | 15/7/2023 | 17/6/2026 | Plane version 0.7.1 allows an unauthenticated attacker to view all stored server files of all users. | |
| Modificada | Crítica (9.8) | 1.0% | — | Planet Wdrt-1800ax Firmware | 7/6/2023 | 17/6/2026 | An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie. | |
| Modificada | Crítica (9.8) | 2.3% | — | Plugin-planet User Submitted Posts | 7/6/2023 | 17/6/2026 | The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may… | |
| Modificada | Media (5.5) | 0.25% | — | Planet | 12/5/2023 | 17/6/2026 | Planet is software that provides satellite data. The secret file stores the user's Planet API authentication information. It should only be accessible by the user, but before version 2.0.1, its permissions allowed the user's group and non-group to read the file as well. This issue was patched in version 2.0.1. As a… | |
| Modificada | Media (4.8) | 0.37% | — | Plugin-planet Dashboard Widget Suite | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions. | |
| Modificada | Media (4.9) | 0.68% | — | Crossplane | 9/3/2023 | 17/6/2026 | crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. In affected versions an already highly privileged user able to create or update Compositions can specify an arbitrarily high index in a patch's `ToFieldPath`, which could lead to excessive memory… | |
| Modificada | Alta (7.5) | 0.80% | — | Crossplane-runtime | 9/3/2023 | 17/6/2026 | crossplane-runtime is a set of go libraries used to build Kubernetes controllers in Crossplane and its related stacks. An out of memory panic vulnerability has been discovered in affected versions. Applications that use the `Paved` type's `SetValue` method with user provided input without proper validation might use… | |
| Modificada | Media (6.1) | 0.51% | — | Planex Cs-wmv02g Firmware | 14/2/2023 | 17/6/2026 | Reflected cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to inject arbitrary script to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer. | |
| Modificada | Alta (8.8) | 0.36% | — | Planex Cs-wmv02g Firmware | 14/2/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a remote unauthenticated attacker to hijack the authentication and conduct arbitrary operations by having a logged-in user to view a malicious page. NOTE: This vulnerability only affects products… | |
| Modificada | Media (5.2) | 0.29% | — | Planex Cs-wmv02g | 14/2/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in Wired/Wireless LAN Pan/Tilt Network Camera CS-WMV02G all versions allows a network-adjacent authenticated attacker to inject an arbitrary script. NOTE: This vulnerability only affects products that are no longer supported by the developer. | |
| Modificada | Media (6.1) | 0.53% | — | Invoiceplane | 7/2/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php. | |
| Modificada | Crítica (9.8) | 0.87% | — | Faplanet Project Faplanet | 16/1/2023 | 17/6/2026 | A vulnerability has been found in frontaccounting faplanet and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal. The patch is identified as a5dcd87f46080a624b1a9ad4b0dd035bbd24ac50. It is recommended to apply a patch to fix this issue. VDB-218398 is the… | |
| Modificada | Crítica (9.8) | 1.2% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution. | |
| Modificada | Media (6.5) | 0.74% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoint (e.g., path disclosure). | |
| Modificada | Media (6.5) | 1.0% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files. | |
| Modificada | Alta (8.8) | 0.79% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access. | |
| Modificada | Media (5.4) | 0.44% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username. | |
| Modificada | Crítica (9.1) | 0.73% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList). | |
| Modificada | Media (6.1) | 0.47% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter). |