Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.32% | — | Harmonizers Planet Project Harmonizers Planet | 16/10/2014 | 17/6/2026 | The Harmonizers Planet (aka uk.co.pixelkicks.fifthharmony) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | 5sos Family Planet Project 5sos Family Planet | 24/9/2014 | 17/6/2026 | The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Planetofthevapes Planet OF THE Vapes Forum | 23/9/2014 | 17/6/2026 | The Planet of the Vapes Forum (aka com.tapatalk.planetofthevapescoukforums) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Freshplanet Songpop | 9/9/2014 | 17/6/2026 | The SongPop (aka air.com.freshplanet.games.WaM) application 1.21.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 7.7% | — | Dlink Di-524upDlink Di-604+Dlink Di-604sDlink Di-604up+9 | 19/10/2013 | 16/6/2026 | The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP… | |
| Modificada | Media (4.3) | 3.7% | — | Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+11 | 8/2/2013 | 16/6/2026 | The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical… | |
| Modificada | Media (5) | 2.7% | — | Oracle Iplanet WEB ServerOracle SUN Products Suite Java System WEB Server | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server. | |
| Modificada | Media (5) | 0.95% | — | Iplanet Loganpro | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. | |
| Modificada | Media (4.3) | 0.87% | — | Iplanet Webexpert | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. | |
| Modificada | Media (4.3) | 1.4% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 28/1/2010 | 16/6/2026 | Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486. | |
| Modificada | Media (4.3) | 1.3% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 28/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and… | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Intertwingly PlanetIntertwingly Planet Venus | 18/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | |
| Modificada | Media (5.8) | 2.2% | — | SUN Iplanet WEB ServerSUN ONE WEB Server | 1/6/2009 | 16/6/2026 | The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting. | |
| Modificada | Media (6.8) | 0.57% | — | Planetluc Rateme | 4/11/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Planetluc Rateme | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action. | |
| Modificada | Media (4.3) | 1.1% | — | Planetluc Mygallery | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Planetluc Signme | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (3.5) | 2.4% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the… | |
| Modificada | Media (6) | 2.2% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter. | |
| Modificada | Media (6.8) | 5.4% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Planetluc Mynews | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1. | |
| Modificada | Media (5) | 1.7% | — | Planet Technology Corp Vc-200m Vdsl2 | 22/8/2007 | 16/6/2026 | The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header. | |
| Modificada | Alta (7.5) | 1.4% | — | Planerd.net P-news | 6/3/2007 | 16/6/2026 | Unrestricted file upload vulnerability in P-News 2.0 allows remote attackers to upload and execute arbitrary files via an avatar file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Planerd.net P-news | 6/3/2007 | 16/6/2026 | P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and password hashes via a direct request. NOTE: this might be the same issue as CVE-2006-6888. |