Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
ModificadaMedia (5.4)0.67%—Invoiceplane21/3/201917/6/2026
InvoicePlane 1.5 has stored XSS via the index.php/invoices/ajax/save invoice_password parameter, aka the "PDF password" field to the "Create Invoice" option. The XSS payload is rendered at an index.php/invoices/view/## URI. NOTE: this is different from CVE-2018-12255.
ModificadaCrítica (9.8)3.2%💥 ExploitMultiplanet Alphaindex Dictionaries28/9/201817/6/2026
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
ModificadaCrítica (9.8)1.5%—Planex Cs-qr20 FirmwarePlanex Smacam Night Vision24/8/201817/6/2026
An issue was discovered on the PLANEX CS-QR20 1.30. A hardcoded account / password ("admin:password") is used in the Android application that allows attackers to use a hidden API URL "/goform/SystemCommand" to execute any command with root permission.
ModificadaAlta (7.2)2.2%—Planex Cs-qr20 Firmware24/8/201817/6/2026
An issue was discovered on the PLANEX CS-QR20 1.30. A hidden and undocumented management page allows an attacker to execute arbitrary code on the device when the user is authenticated. The management page was used for debugging purposes, once you login and access the page directly (/admin/system_command.asp), you can…
ModificadaCrítica (9.8)1.8%—Planex Cs-w50hd Firmware24/8/201817/6/2026
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. A hardcoded credential "supervisor:dangerous" was injected into web authentication database "/.htpasswd" during booting process, which allows attackers to gain unauthorized access and control the device completely; the account can't be…
ModificadaAlta (8.8)3.1%—Planex Cs-w50hd Firmware24/8/201817/6/2026
An issue was discovered on PLANEX CS-W50HD devices with firmware before 030720. The device has a command-injection vulnerability in the web management UI on NAS settings page "/cgi-bin/nasset.cgi". An attacker can send a crafted HTTP POST request to execute arbitrary code. Authentication is required before executing…
ModificadaMedia (6.1)0.72%—Invoiceplane3/7/201817/6/2026
An XSS issue was discovered in InvoicePlane 1.5.10 via the "Quote PDF Password(Optional)" field.
ModificadaMedia (6.1)0.85%—Canonical Ubuntu LinuxRedhat Ceph StorageRedhat Enterprise Linux Fast DatapathRedhat Openshift+524/4/201817/6/2026
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are…
ModificadaMedia (5.5)2.6%—FreeplaneDebian Linux13/3/201817/6/2026
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.
ModificadaMedia (6.1)1.3%—Invoiceplane5/3/201817/6/2026
An issue was discovered in InvoicePlane before 1.5.5. It was observed that the Email address and Web address parameters are vulnerable to Cross Site Scripting, related to application/modules/clients/views/view.php, application/modules/invoices/views/view.php, and application/modules/quotes/views/view.php.
ModificadaMedia (6.1)1.0%—Invoiceplane9/2/201817/6/2026
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.
ModificadaMedia (5.4)0.48%—Invoiceplane17/11/201717/6/2026
InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.
ModificadaAlta (8.8)1.1%—Invoiceplane17/11/201717/6/2026
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.
ModificadaMedia (6.1)1.4%—Oracle Iplanet WEB Server19/10/201717/6/2026
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server.…
ModificadaMedia (6.1)0.64%—Objectplanet Opinio3/7/201717/6/2026
In ObjectPlanet Opinio before 7.6.4, there is XSS.
ModificadaMedia (6.1)0.87%—Bilboplanet24/2/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
ModificadaAlta (8.8)4.2%—Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+813/3/201617/6/2026
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
ModificadaCrítica (9.8)10%—Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+35/11/201517/6/2026
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
ModificadaMedia (4.3)1.9%—Unitedplanet Intrexx19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
ModificadaMedia (5.4)0.29%—Gcspublishing Biplane Forum20/10/201417/6/2026
The Biplane Forum (aka com.gcspublishing.biplaneforum) application 3.7.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nashaplaneta.su19/10/201417/6/2026
The nashaplaneta.su (aka com.wNashaPlaneta) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.29%—IM5 Fans Planet Project IM5 Fans Planet19/10/201417/6/2026
The IM5 Fans Planet (aka uk.co.pixelkicks.im5) application 2.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades