Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter). | |
| Modificada | Media (6.8) | 0.37% | — | Planex Cs-qr20 FirmwarePlanex Cs-qr10 Firmware | 8/9/2022 | 17/6/2026 | Missing protection mechanism for alternate hardware interface in SmaCam CS-QR10 all versions and SmaCam Night Vision CS-QR20 all versions allows an attacker to execute an arbitrary OS command by having the product connect to the product's specific serial connection | |
| Modificada | Alta (8.6) | 2.2% | — | Nvidia Data Plane Development KIT | 1/9/2022 | 17/6/2026 | NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality. | |
| Modificada | Alta (8.6) | 2.2% | — | Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+4 | 31/8/2022 | 17/6/2026 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | |
| Modificada | Media (6.5) | 0.30% | — | Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform | 29/8/2022 | 17/6/2026 | A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts… | |
| Modificada | Alta (7.5) | 1.6% | — | Dpdk Data Plane Development KITFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Fast Datapath | 23/8/2022 | 17/6/2026 | A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability. | |
| Modificada | Alta (7.2) | 1.7% | — | Planex Mzk-dp150n Firmware | 22/8/2022 | 17/6/2026 | Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system command as root via etc_ro/web/syscmd.asp. | |
| Modificada | Crítica (9.8) | 4.2% | — | Proietti Planet Time Enterprise | 17/6/2022 | 17/6/2026 | Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter. | |
| Modificada | Crítica (9.8) | 17% | 💥 PoC | Redplanetcomputers Laundry Management System | 29/4/2022 | 17/6/2026 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | |
| Modificada | Media (4.3) | 0.40% | — | Plugin-planet Simple Ajax Chat | 15/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Plugin-planet Simple Ajax Chat | 15/4/2022 | 17/6/2026 | Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115 | |
| Modificada | Alta (7.8) | 0.30% | — | Blueplanet-works Appguard | 12/4/2022 | 17/6/2026 | AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user. | |
| Modificada | Crítica (9.1) | 1.7% | — | Plugin-planet Blackhole FOR BAD Bots | 4/4/2022 | 17/6/2026 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots.… | |
| Modificada | Media (6.1) | 0.72% | — | Plugin-planet Simple Ajax Chat | 25/3/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit. | |
| Modificada | Media (6.1) | 1.0% | — | Plugin-planet Contact Form XFedoraproject Fedora | 11/3/2022 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). | |
| Modificada | Crítica (9.8) | 0.97% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be… | |
| Modificada | Crítica (9.8) | 1.0% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection.… | |
| Modificada | Crítica (9.8) | 0.81% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**:… | |
| Modificada | Alta (8.8) | 1.1% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject… | |
| Modificada | Alta (7.5) | 0.62% | — | Planetargon OH MY ZSH | 12/11/2021 | 17/6/2026 | ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command | |
| Modificada | Alta (8.8) | 6.0% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code. | |
| Modificada | Alta (7.5) | 1.7% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data. | |
| Modificada | Media (6.5) | 1.1% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can… | |
| Modificada | Media (6.1) | 0.98% | — | Objectplanet Opinio | 30/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.) | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Plugin-planet Prismatic | 12/7/2021 | 17/6/2026 | The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator |