Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%💥 ExploitLushiwarplaner9/2/200716/6/2026
SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)3.9%💥 ExploitSUN Iplanet WEB Server12/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.8%💥 ExploitPlanetluc.com Rateme20/12/200616/6/2026
PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter.
ModificadaMedia (4.3)1.7%💥 ExploitSUN Iplanet Messaging Server Messenger Express3/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486,…
ModificadaMedia (4.3)2.0%—SUN Iplanet Messaging ServerSUN Java System Messaging Server24/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
ModificadaMedia (5.1)1.7%—Planet Concept Planetgallery24/7/200616/6/2026
admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types.
ModificadaAlta (10)6.2%—Planet Concept Planetnews13/7/200616/6/2026
PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php.
ModificadaBaja (2.1)0.34%—SUN Iplanet Messaging ServerSUN ONE Messaging Server22/6/200616/6/2026
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.
ModificadaMedia (6.8)2.2%—Planete Afrique Ws-album15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters.
ModificadaAlta (7.5)1.5%—Planet Concept Planetstat12/5/200616/6/2026
PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page.
ModificadaMedia (4.3)1.9%💥 ExploitPlanetluc Mynews5/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.
ModificadaAlta (7.5)2.7%💥 ExploitPlanet Concept Planetgallery1/5/200616/6/2026
planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.
ModificadaMedia (4.3)1.9%💥 ExploitPlanet Concept Planetsearch+18/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.
ModificadaMedia (4.6)0.35%—Planet Technology Corp Fgsw2402rs14/10/200516/6/2026
Planet Technology Corp FGSW2402RS switch with firmware 1.2 has a default password, which allows attackers with physical access to the device's serial port to gain privileges.
ModificadaMedia (5)1.3%—Planetdns Planetfileserver6/7/200516/6/2026
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.
ModificadaMedia (4.3)0.94%—SUN Iplanet Messaging ServerSUN ONE Messaging Server17/6/200516/6/2026
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripting (XSS) vulnerability.
ModificadaMedia (4.3)1.7%💥 Exploit12planet Chat Server6/8/200416/6/2026
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter.
ModificadaMedia (5)3.0%💥 ExploitPlanetmoon Guestbook31/12/200316/6/2026
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt.
ModificadaAlta (10)2.2%—Planet Technology Corp Wgsd-1020Planet Technology Corp Wsw-240131/12/200316/6/2026
Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.
ModificadaMedia (5)1.6%—SUN Iplanet Directory ServerSUN ONE Directory Server27/8/200316/6/2026
Directory traversal vulnerability in ViewLog for iPlanet Administration Server 5.1 (aka Sun ONE) allows remote attackers to read arbitrary files via "..%2f" (partially encoded dot dot) sequences.
ModificadaAlta (7.5)11%💥 ExploitPlanetdns Planetweb2/4/200316/6/2026
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long URL or (2) a request with a long method name.
ModificadaMedia (5)2.3%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.
ModificadaAlta (7.5)2.6%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
ModificadaMedia (6.8)1.6%—Iplanet WEB Server29/11/200216/6/2026
Cross-site scripting (XSS) vulnerability in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows remote attackers to execute web script or HTML as the iPlanet administrator by injecting the desired script into error logs, and possibly escalating privileges by using the XSS vulnerability in conjunction with…
ModificadaMedia (6.8)2.0%—Iplanet WEB Server29/11/200216/6/2026
importInfo in the Admin Server for iPlanet WebServer 4.x, up to SP11, allows the web administrator to execute arbitrary commands via shell metacharacters in the dir parameter, and possibly allows remote attackers to exploit this vulnerability via a separate XSS issue (CVE-2002-1315).
Orbitaley — Vulnerabilidades