Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

235 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—SUN Iplanet Messaging ServerSUN ONE Messaging Server28/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and…
ModificadaMedia (4.3)4.5%💥 ExploitIntertwingly PlanetIntertwingly Planet Venus18/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.
ModificadaMedia (5.8)2.2%—SUN Iplanet WEB ServerSUN ONE WEB Server1/6/200916/6/2026
The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.
ModificadaMedia (6.8)0.57%—Planetluc Rateme4/11/200816/6/2026
Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.
ModificadaMedia (4.3)1.0%—Planetluc Rateme4/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.
ModificadaMedia (4.3)1.1%—Planetluc Mygallery4/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.1%—Planetluc Signme4/11/200816/6/2026
Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6)2.2%💥 ExploitTuxplanet Bilboblog25/7/200816/6/2026
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.
ModificadaBaja (3.5)2.4%💥 ExploitTuxplanet Bilboblog25/7/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in BilboBlog 0.2.1 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) content parameter to admin/update.php, related to conflicting code in widget.php; and allow remote attackers to inject arbitrary web script or HTML via the…
ModificadaMedia (5)6.1%💥 ExploitTuxplanet Bilboblog25/7/200816/6/2026
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.
ModificadaMedia (6.8)5.4%💥 ExploitTuxplanet Bilboblog25/7/200816/6/2026
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.
ModificadaMedia (4.3)1.4%💥 ExploitPlanetluc Mynews12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.
ModificadaMedia (5)1.7%—Planet Technology Corp Vc-200m Vdsl222/8/200716/6/2026
The administration interface in the Planet VC-200M VDSL2 router allows remote attackers to cause a denial of service (administration interface outage) via an HTTP request without a Host header.
ModificadaMedia (6.8)3.9%💥 ExploitSUN Iplanet WEB Server12/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in /search in iPlanet Web Server 4.x allows remote attackers to inject arbitrary web script or HTML via the NS-max-records parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.8%💥 ExploitPlanetluc.com Rateme20/12/200616/6/2026
PHP remote file inclusion vulnerability in main.inc.php in planetluc.com RateMe 1.3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtoscript parameter.
ModificadaMedia (4.3)1.7%💥 ExploitSUN Iplanet Messaging Server Messenger Express3/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486,…
ModificadaMedia (4.3)2.0%—SUN Iplanet Messaging ServerSUN Java System Messaging Server24/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in Webmail in Sun Java System Messaging Server 6.0 through 6.2 and iPlanet Messaging Server 5.2 allows remote attackers to execute arbitrary Javascript via crafted messages.
ModificadaMedia (5.1)1.7%—Planet Concept Planetgallery24/7/200616/6/2026
admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types.
ModificadaAlta (10)6.2%—Planet Concept Planetnews13/7/200616/6/2026
PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php.
ModificadaBaja (2.1)0.34%—SUN Iplanet Messaging ServerSUN ONE Messaging Server22/6/200616/6/2026
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns the first line of the file in an error message.
ModificadaMedia (6.8)2.2%—Planete Afrique Ws-album15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FullPhoto.asp in WS-Album 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) image and (2) PublisedDate parameters.
ModificadaAlta (7.5)1.5%—Planet Concept Planetstat12/5/200616/6/2026
PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page.
ModificadaMedia (4.3)1.9%💥 ExploitPlanetluc Mynews5/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.
ModificadaAlta (7.5)2.7%💥 ExploitPlanet Concept Planetgallery1/5/200616/6/2026
planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.
ModificadaMedia (4.3)1.9%💥 ExploitPlanet Concept Planetsearch+18/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.