Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 28/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and… | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Intertwingly PlanetIntertwingly Planet Venus | 18/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | |
| Modificada | Media (5.8) | 2.2% | — | SUN Iplanet WEB ServerSUN ONE WEB Server | 1/6/2009 | 16/6/2026 | The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting. | |
| Modificada | Media (6.8) | 0.57% | — | Planetluc Rateme | 4/11/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Planetluc Rateme | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action. | |
| Modificada | Media (4.3) | 1.1% | — | Planetluc Mygallery | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Planetluc Signme | 4/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6) | 2.2% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter. | |
| Modificada | Baja (3.5) | 2.4% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the… | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message. | |
| Modificada | Media (6.8) | 5.4% | 💥 Exploit | Tuxplanet Bilboblog | 25/7/2008 | 16/6/2026 | admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Planetluc Mynews | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1. | |
| Modificada | Media (5) | 1.7% | — | Planet Technology Corp Vc-200m Vdsl2 | 22/8/2007 | 16/6/2026 | The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | SUN Iplanet WEB Server | 12/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Planetluc.com Rateme | 20/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | SUN Iplanet Messaging Server Messenger Express | 3/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486,… | |
| Modificada | Media (4.3) | 2.0% | — | SUN Iplanet Messaging ServerSUN Java System Messaging Server | 24/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages. | |
| Modificada | Media (5.1) | 1.7% | — | Planet Concept Planetgallery | 24/7/2006 | 16/6/2026 | admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. | |
| Modificada | Alta (10) | 6.2% | — | Planet Concept Planetnews | 13/7/2006 | 16/6/2026 | PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php. | |
| Modificada | Baja (2.1) | 0.34% | — | SUN Iplanet Messaging ServerSUN ONE Messaging Server | 22/6/2006 | 16/6/2026 | pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message. | |
| Modificada | Media (6.8) | 2.2% | — | Planete Afrique Ws-album | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Planet Concept Planetstat | 12/5/2006 | 16/6/2026 | PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planetluc Mynews | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Planet Concept Planetgallery | 1/5/2006 | 16/6/2026 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planet Concept Planetsearch+ | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter. |