Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Lushiwarplaner | 9/2/2007 | 16/6/2026 | SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | SUN Iplanet WEB Server | 12/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Planetluc.com Rateme | 20/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | SUN Iplanet Messaging Server Messenger Express | 3/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486,… | |
| Modificada | Media (4.3) | 2.0% | — | SUN Iplanet Messaging ServerSUN Java System Messaging Server | 24/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages. | |
| Modificada | Media (5.1) | 1.7% | — | Planet Concept Planetgallery | 24/7/2006 | 16/6/2026 | admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. | |
| Modificada | Alta (10) | 6.2% | — | Planet Concept Planetnews | 13/7/2006 | 16/6/2026 | PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php. | |
| Modificada | Baja (2.1) | 0.34% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 22/6/2006 | 16/6/2026 | pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message. | |
| Modificada | Media (6.8) | 2.2% | — | Planete Afrique Ws-album | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Planet Concept Planetstat | 12/5/2006 | 16/6/2026 | PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planetluc Mynews | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Planet Concept Planetgallery | 1/5/2006 | 16/6/2026 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planet Concept Planetsearch+ | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter. | |
| Modificada | Media (4.6) | 0.35% | — | Planet Technology Corp Fgsw2402rs | 14/10/2005 | 16/6/2026 | Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | Planetdns Planetfileserver | 6/7/2005 | 16/6/2026 | mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. | |
| Modificada | Media (4.3) | 0.94% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 17/6/2005 | 16/6/2026 | Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | 12planet Chat Server | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Planetmoon Guestbook | 31/12/2003 | 16/6/2026 | PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt. | |
| Modificada | Alta (10) | 2.2% | — | Planet Technology Corp Wgsd-1020Planet Technology Corp Wsw-2401 | 31/12/2003 | 16/6/2026 | Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access. | |
| Modificada | Media (5) | 1.6% | — | SUN Iplanet Directory ServerSUN ONE Directory Server | 27/8/2003 | 16/6/2026 | Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Planetdns Planetweb | 2/4/2003 | 16/6/2026 | Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name. | |
| Modificada | Media (5) | 2.3% | — | Iplanet WEB ServerNetscape Enterprise Server | 31/12/2002 | 16/6/2026 | The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request. | |
| Modificada | Alta (7.5) | 2.6% | — | Iplanet WEB ServerNetscape Enterprise Server | 31/12/2002 | 16/6/2026 | iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection. | |
| Modificada | Media (6.8) | 1.6% | — | Iplanet WEB Server | 29/11/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with… | |
| Modificada | Media (6.8) | 2.0% | — | Iplanet WEB Server | 29/11/2002 | 16/6/2026 | importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315). |