Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.3% | 💥 Exploit | Oracle Iplanet WEB Server | 10/5/2020 | 17/6/2026 | ** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com… | |
| Modificada | Crítica (9.8) | 4.0% | — | Unitedplanet Intrexx | 31/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Czepol Wp-planet | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Plugin-planet User Submitted Posts | 20/9/2019 | 17/6/2026 | The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field. | |
| Modificada | Media (6.1) | 0.80% | — | Bilboplanet | 15/5/2019 | 17/6/2026 | An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php. | |
| Modificada | Media (6.1) | 0.80% | — | Bilboplanet | 15/5/2019 | 17/6/2026 | An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php. | |
| Modificada | Media (6.1) | 0.80% | — | Bilboplanet | 15/5/2019 | 17/6/2026 | An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter. | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Multiplanet Alphaindex Dictionaries | 28/9/2018 | 17/6/2026 | SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter. | |
| Modificada | Media (6.1) | 1.4% | — | Oracle Iplanet WEB Server | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server.… | |
| Modificada | Media (6.1) | 0.64% | — | Objectplanet Opinio | 3/7/2017 | 17/6/2026 | In ObjectPlanet Opinio before 7.6.4, there is XSS. | |
| Modificada | Media (6.1) | 0.87% | — | Bilboplanet | 24/2/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php. | |
| Modificada | Alta (8.8) | 4.2% | — | Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+8 | 13/3/2016 | 17/6/2026 | Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate. | |
| Modificada | Crítica (9.8) | 10% | — | Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+3 | 5/11/2015 | 17/6/2026 | Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | |
| Modificada | Media (4.3) | 1.9% | — | Unitedplanet Intrexx | 19/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Nashaplaneta.su | 19/10/2014 | 17/6/2026 | The nashaplaneta.su (aka com.wNashaPlaneta) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | IM5 Fans Planet Project IM5 Fans Planet | 19/10/2014 | 17/6/2026 | The IM5 Fans Planet (aka uk.co.pixelkicks.im5) application 2.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.32% | — | Harmonizers Planet Project Harmonizers Planet | 16/10/2014 | 17/6/2026 | The Harmonizers Planet (aka uk.co.pixelkicks.fifthharmony) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | 5sos Family Planet Project 5sos Family Planet | 24/9/2014 | 17/6/2026 | The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Planetofthevapes Planet OF THE Vapes Forum | 23/9/2014 | 17/6/2026 | The Planet of the Vapes Forum (aka com.tapatalk.planetofthevapescoukforums) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Freshplanet Songpop | 9/9/2014 | 17/6/2026 | The SongPop (aka air.com.freshplanet.games.WaM) application 1.21.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.7% | — | Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+11 | 8/2/2013 | 16/6/2026 | The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical… | |
| Modificada | Media (5) | 2.7% | — | Oracle Iplanet WEB ServerOracle SUN Products Suite Java System WEB Server | 17/7/2012 | 16/6/2026 | Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server. | |
| Modificada | Media (5) | 0.95% | — | Iplanet Loganpro | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. | |
| Modificada | Media (4.3) | 0.87% | — | Iplanet Webexpert | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header. | |
| Modificada | Media (4.3) | 1.4% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 28/1/2010 | 16/6/2026 | Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486. |