Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

235 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)1.3%💥 ExploitOracle Iplanet WEB Server10/5/202017/6/2026
** PRODUCT NOT SUPPORTED WHEN ASSIGNED ** Oracle iPlanet Web Server 7.0.x allows image injection in the Administration console via the productNameSrc parameter to an admingui URI. This issue exists because of an incomplete fix for CVE-2012-0516. NOTE: a related support policy can be found in the www.oracle.com…
ModificadaCrítica (9.8)4.0%—Unitedplanet Intrexx31/1/202017/6/2026
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.
ModificadaMedia (6.1)4.0%💥 ExploitCzepol Wp-planet27/12/201917/6/2026
Cross-site scripting (XSS) vulnerability in rss.class/scripts/magpie_debug.php in the WP-Planet plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
ModificadaMedia (6.1)1.2%—Plugin-planet User Submitted Posts20/9/201917/6/2026
The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.
ModificadaMedia (6.1)0.80%—Bilboplanet15/5/201917/6/2026
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.
ModificadaCrítica (9.8)3.2%💥 ExploitMultiplanet Alphaindex Dictionaries28/9/201817/6/2026
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
ModificadaMedia (6.1)1.4%—Oracle Iplanet WEB Server19/10/201717/6/2026
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server.…
ModificadaMedia (6.1)0.64%—Objectplanet Opinio3/7/201717/6/2026
In ObjectPlanet Opinio before 7.6.4, there is XSS.
ModificadaMedia (6.1)0.87%—Bilboplanet24/2/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.
ModificadaAlta (8.8)4.2%—Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+813/3/201617/6/2026
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
ModificadaCrítica (9.8)10%—Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+35/11/201517/6/2026
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
ModificadaMedia (4.3)1.9%—Unitedplanet Intrexx19/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
ModificadaMedia (5.4)0.27%—Nashaplaneta.su19/10/201417/6/2026
The nashaplaneta.su (aka com.wNashaPlaneta) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.29%—IM5 Fans Planet Project IM5 Fans Planet19/10/201417/6/2026
The IM5 Fans Planet (aka uk.co.pixelkicks.im5) application 2.3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.32%—Harmonizers Planet Project Harmonizers Planet16/10/201417/6/2026
The Harmonizers Planet (aka uk.co.pixelkicks.fifthharmony) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—5sos Family Planet Project 5sos Family Planet24/9/201417/6/2026
The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Planetofthevapes Planet OF THE Vapes Forum23/9/201417/6/2026
The Planet of the Vapes Forum (aka com.tapatalk.planetofthevapescoukforums) application 3.7.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Freshplanet Songpop9/9/201417/6/2026
The SongPop (aka air.com.freshplanet.games.WaM) application 1.21.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)3.7%—Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+118/2/201316/6/2026
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical…
ModificadaMedia (5)2.7%—Oracle Iplanet WEB ServerOracle SUN Products Suite Java System WEB Server17/7/201216/6/2026
Unspecified vulnerability in the Oracle iPlanet Web Server component in Oracle Sun Products Suite Java System Web Server 6.1 and Oracle iPlanet Web Server 7.0 allows remote attackers to affect availability via unknown vectors related to Web Server.
ModificadaMedia (5)0.95%—Iplanet Loganpro5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
ModificadaMedia (4.3)0.87%—Iplanet Webexpert5/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.
ModificadaMedia (4.3)1.4%—SUN Iplanet Messaging ServerSUN ONE Messaging Server28/1/201016/6/2026
Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.