Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.73% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList). | |
| Modificada | Media (6.1) | 0.47% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter). | |
| Modificada | Alta (7.2) | 1.3% | — | Planetestream Planet Estream | 25/12/2022 | 17/6/2026 | Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter). | |
| Modificada | Crítica (9.8) | 4.2% | — | Proietti Planet Time Enterprise | 17/6/2022 | 17/6/2026 | Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter. | |
| Modificada | Crítica (9.8) | 17% | 💥 PoC | Redplanetcomputers Laundry Management System | 29/4/2022 | 17/6/2026 | Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection. | |
| Modificada | Media (4.3) | 0.40% | — | Plugin-planet Simple Ajax Chat | 15/4/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Plugin-planet Simple Ajax Chat | 15/4/2022 | 17/6/2026 | Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115 | |
| Modificada | Alta (7.8) | 0.30% | — | Blueplanet-works Appguard | 12/4/2022 | 17/6/2026 | AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user. | |
| Modificada | Crítica (9.1) | 1.7% | — | Plugin-planet Blackhole FOR BAD Bots | 4/4/2022 | 17/6/2026 | The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots.… | |
| Modificada | Media (6.1) | 0.72% | — | Plugin-planet Simple Ajax Chat | 25/3/2022 | 17/6/2026 | Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit. | |
| Modificada | Media (6.1) | 1.0% | — | Plugin-planet Contact Form XFedoraproject Fedora | 11/3/2022 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). | |
| Modificada | Crítica (9.8) | 0.97% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be… | |
| Modificada | Crítica (9.8) | 1.0% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection.… | |
| Modificada | Crítica (9.8) | 0.81% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**:… | |
| Modificada | Alta (8.8) | 1.1% | — | Planetargon OH MY ZSH | 30/11/2021 | 17/6/2026 | Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject… | |
| Modificada | Alta (7.5) | 0.62% | — | Planetargon OH MY ZSH | 12/11/2021 | 17/6/2026 | ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command | |
| Modificada | Alta (8.8) | 6.0% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code. | |
| Modificada | Alta (7.5) | 1.7% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data. | |
| Modificada | Media (6.5) | 1.1% | — | Objectplanet Opinio | 31/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can… | |
| Modificada | Media (6.1) | 0.98% | — | Objectplanet Opinio | 30/7/2021 | 17/6/2026 | ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.) | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Plugin-planet Prismatic | 12/7/2021 | 17/6/2026 | The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator | |
| Modificada | Media (5.4) | 0.62% | — | Plugin-planet Prismatic | 12/7/2021 | 17/6/2026 | The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however,… | |
| Modificada | Crítica (9.8) | 1.8% | — | Planet Nvr-915 FirmwarePlanet Nvr-1615 Firmware | 18/11/2020 | 17/6/2026 | The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (6.1) | 0.83% | — | Unitedplanet Intrexx | 14/10/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Alta (7.5) | 82% | 💥 Exploit | Oracle Iplanet WEB Server | 10/5/2020 | 17/6/2026 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to… |