Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

235 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.73%—Planetestream Planet Estream25/12/202217/6/2026
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
ModificadaMedia (6.1)0.47%—Planetestream Planet Estream25/12/202217/6/2026
In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).
ModificadaAlta (7.2)1.3%—Planetestream Planet Estream25/12/202217/6/2026
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
ModificadaCrítica (9.8)4.2%—Proietti Planet Time Enterprise17/6/202217/6/2026
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.
ModificadaCrítica (9.8)17%💥 PoCRedplanetcomputers Laundry Management System29/4/202217/6/2026
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
ModificadaMedia (4.3)0.40%—Plugin-planet Simple Ajax Chat15/4/202217/6/2026
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
ModificadaAlta (7.5)4.6%💥 ExploitPlugin-planet Simple Ajax Chat15/4/202217/6/2026
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
ModificadaAlta (7.8)0.30%—Blueplanet-works Appguard12/4/202217/6/2026
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
ModificadaCrítica (9.1)1.7%—Plugin-planet Blackhole FOR BAD Bots4/4/202217/6/2026
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots.…
ModificadaMedia (6.1)0.72%—Plugin-planet Simple Ajax Chat25/3/202217/6/2026
Unauthenticated Stored Cross-Site Scripting (XSS) in Simple Ajax Chat <= 20220115 allows an attacker to store the malicious code. However, the attack requires specific conditions, making it hard to exploit.
ModificadaMedia (6.1)1.0%—Plugin-planet Contact Form XFedoraproject Fedora11/3/202217/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
ModificadaCrítica (9.8)0.97%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a specially-crafted name the vulnerability can be…
ModificadaCrítica (9.8)1.0%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols, they could trigger command injection.…
ModificadaCrítica (9.8)0.81%—Planetargon OH MY ZSH30/11/202117/6/2026
# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function in a way that is unsafe. **Fixed in**:…
ModificadaAlta (8.8)1.1%—Planetargon OH MY ZSH30/11/202117/6/2026
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name, then press Alt-Left, the system is subject…
ModificadaAlta (7.5)0.62%—Planetargon OH MY ZSH12/11/202117/6/2026
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
ModificadaAlta (8.8)6.0%—Objectplanet Opinio31/7/202117/6/2026
admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
ModificadaAlta (7.5)1.7%—Objectplanet Opinio31/7/202117/6/2026
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data.
ModificadaMedia (6.5)1.1%—Objectplanet Opinio31/7/202117/6/2026
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can…
ModificadaMedia (6.1)0.98%—Objectplanet Opinio30/7/202117/6/2026
ObjectPlanet Opinio before 7.14 allows reflected XSS via the survey/admin/surveyAdmin.do?action=viewSurveyAdmin query string. (There is also stored XSS if input to survey/admin/*.do is accepted from untrusted users.)
ModificadaMedia (6.1)1.7%💥 ExploitPlugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
ModificadaMedia (5.4)0.62%—Plugin-planet Prismatic12/7/202117/6/2026
The Prismatic WordPress plugin before 2.8 does not sanitise or validate some of its shortcode parameters, allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS trigger able in the frontend, however,…
ModificadaCrítica (9.8)1.8%—Planet Nvr-915 FirmwarePlanet Nvr-1615 Firmware18/11/202017/6/2026
The firmware of the PLANET Technology Corp NVR-915 and NVR-1615 before 2020-10-28 embeds default credentials for root access via telnet. By exposing telnet on the Internet, remote root access on the device is possible. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaMedia (6.1)0.83%—Unitedplanet Intrexx14/10/202017/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
ModificadaAlta (7.5)82%💥 ExploitOracle Iplanet WEB Server10/5/202017/6/2026
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x has Incorrect Access Control for admingui/version URIs in the Administration console, as demonstrated by unauthenticated read access to encryption keys. NOTE: a related support policy can be found in the www.oracle.com references attached to…