Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.39% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges. | |
| Analizada | Media (6.8) | 0.27% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password. | |
| Analizada | Alta (8.8) | 0.49% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell. | |
| Modificada | Media (6.1) | 0.26% | — | Planex Cs-qr10 FirmwarePlanex Cs-qr20 FirmwarePlanex Cs-qr22 FirmwarePlanex Cs-qr220 Firmware+1 | 26/9/2024 | 17/6/2026 | Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logged-in user accesses a specific file, an arbitrary script may be executed on the web browser of the user. | |
| Modificada | Media (6.5) | 0.19% | — | Planex Mzk-dp300n Firmware | 26/9/2024 | 17/6/2026 | MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc. | |
| Modificada | Alta (8.7) | 0.40% | — | Planetfitness Planet Fitness Workouts | 23/9/2024 | 17/6/2026 | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in… | |
| Analizada | Media (4.8) | 0.42% | — | Plugin-planet User Submitted Posts | 13/7/2024 | 17/6/2026 | The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.37% | — | Plugin-planet Dashboard Widgets Suite | 13/6/2024 | 17/6/2026 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (5.4) | 0.33% | — | Plugin-planet Simple Ajax Chat | 4/6/2024 | 17/6/2026 | The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 1.0% | — | Planex Mzk-mf300n FirmwarePlanex Mzk-mf300hp2 Firmware | 15/4/2024 | 17/6/2026 | Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N is no longer supported, therefore the update for this product is not provided. | |
| Analizada | Media (6.8) | 0.29% | — | Planex Mzk-mf300n FirmwarePlanex Mzk-mf300hp2 Firmware | 15/4/2024 | 17/6/2026 | Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the device's management page, an unintended operation may be performed. Note that MZK-MF300N is no longer supported, therefore the update for this product is not… | |
| Aplazada | Media (6.4) | 0.50% | — | Planet Igs-4215-16t2sAI | 11/4/2024 | 17/6/2026 | Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could execute arbitrary code on the remote host by exploiting IP address functionality. | |
| Aplazada | Alta (7.1) | 0.22% | — | Planet Igs-4215-16t2sAI | 11/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to trick some authenticated users into performing actions in their session, such as adding or updating accounts through the Switch web interface. | |
| Aplazada | Alta (7.7) | 0.35% | — | Planet Igs-4215-16t2sAI | 11/4/2024 | 17/6/2026 | Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack of proper management of the Switch web interface. | |
| Aplazada | Crítica (9.1) | 0.67% | — | PlaneAI | 10/4/2024 | 17/6/2026 | Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to send arbitrary requests from the server hosting the application, potentially leading to unauthorized access to internal systems. The impact of this… | |
| Aplazada | Media (4.4) | 0.33% | — | Plugin-planet Simple Ajax ChatAI | 27/3/2024 | 17/6/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20231101 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Media (6.5) | 0.34% | — | Plugin-planet User Submitted PostsAI | 26/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS.This issue affects User Submitted Posts: from n/a through 20230901. | |
| Analizada | Alta (7.1) | 0.45% | — | Plugin-planet Simple Ajax Chat | 20/3/2024 | 17/6/2026 | The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized to other users. | |
| Analizada | Alta (8) | 0.45% | — | Ciena Blue Planet Inventory | 6/3/2024 | 17/6/2026 | In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products. Customers are advised to upgrade their Blue… | |
| Modificada | Media (5.9) | 0.62% | — | Samwilson Planet-freo | 4/2/2024 | 17/6/2026 | A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/inc/auth.inc.php. The manipulation of the argument auth leads to incorrect comparison. The attack may be launched remotely. The complexity of an attack is rather… | |
| Modificada | Crítica (9.8) | 0.74% | — | Objectplanet Opinio | 1/2/2024 | 17/6/2026 | Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application. | |
| Modificada | Alta (8.8) | 0.35% | — | Wp-blogs-planetarium Project Wp-blogs-planetarium | 8/1/2024 | 17/6/2026 | The WP Blogs' Planetarium WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Crítica (9.8) | 0.90% | — | Plugin-planet User Submitted Posts | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902. | |
| Modificada | Media (4.8) | 0.39% | — | Plugin-planet Dashboard Widget Suite | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1. | |
| Modificada | Media (5.4) | 0.44% | — | Plugin-planet Theme Switcha | 20/10/2023 | 17/6/2026 | The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… |