Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.3%—Planetestream Planet Estream25/12/202217/6/2026
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
ModificadaMedia (6.8)0.37%—Planex Cs-qr20 FirmwarePlanex Cs-qr10 Firmware8/9/202217/6/2026
Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection
ModificadaAlta (8.6)2.2%—Nvidia Data Plane Development KIT1/9/202217/6/2026
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
ModificadaAlta (8.6)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+431/8/202217/6/2026
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
ModificadaMedia (6.5)0.30%—Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform29/8/202217/6/2026
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts…
ModificadaAlta (7.5)1.6%—Dpdk Data Plane Development KITFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Fast Datapath23/8/202217/6/2026
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
ModificadaAlta (7.2)1.7%—Planex Mzk-dp150n Firmware22/8/202217/6/2026
Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp.
ModificadaCrítica (9.8)4.2%—Proietti Planet Time Enterprise17/6/202217/6/2026
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.
ModificadaCrítica (9.8)17%💥 PoCRedplanetcomputers Laundry Management System29/4/202217/6/2026
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
ModificadaMedia (4.3)0.40%—Plugin-planet Simple Ajax Chat15/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
ModificadaAlta (7.5)4.6%💥 ExploitPlugin-planet Simple Ajax Chat15/4/202217/6/2026
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
ModificadaAlta (7.8)0.30%—Blueplanet-works Appguard12/4/202217/6/2026
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
ModificadaCrítica (9.1)1.7%—Plugin-planet Blackhole FOR BAD Bots4/4/202217/6/2026
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots.…
ModificadaMedia (6.1)0.72%—Plugin-planet Simple Ajax Chat25/3/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.
ModificadaMedia (6.1)1.0%—Plugin-planet Contact Form XFedoraproject Fedora11/3/202217/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
ModificadaCrítica (9.8)0.97%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be…
ModificadaCrítica (9.8)1.0%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection.…
ModificadaCrítica (9.8)0.81%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**:…
ModificadaAlta (8.8)1.1%—Planetargon OH MY ZSH30/11/202117/6/2026
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject…
ModificadaAlta (7.5)0.62%—Planetargon OH MY ZSH12/11/202117/6/2026
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
ModificadaAlta (8.8)6.0%—Objectplanet Opinio31/7/202117/6/2026
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
ModificadaAlta (7.5)1.7%—Objectplanet Opinio31/7/202117/6/2026
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
ModificadaMedia (6.5)1.1%—Objectplanet Opinio31/7/202117/6/2026
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can…
ModificadaMedia (6.1)0.98%—Objectplanet Opinio30/7/202117/6/2026
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
ModificadaMedia (6.1)1.7%💥 ExploitPlugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator