Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.51% | — | Creatives Planet EmphiresAI | 8/4/2026 | 24/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9. | |
| Aplazada | Baja (1.9) | 0.15% | — | Investory TOY Planet Trouble APPAI | 3/4/2026 | 24/7/2026 | A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function of the file assets/google-services-desktop.json of the component app.investory.toyfactory. The manipulation of the argument current_key results in use of hard-coded cryptographic key . The attack… | |
| Aplazada | Alta (7.2) | 0.51% | — | Plugin-planet Blackhole FOR BAD BotsAI | 26/3/2026 | 17/6/2026 | The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP header in all versions up to and including 3.8. This is due to insufficient input sanitization and output escaping. The plugin uses sanitize_text_field() when capturing bot data (which strips HTML tags… | |
| Aplazada | Media (6.4) | 0.42% | — | Plugin-planet Simple Download CounterAI | 26/3/2026 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sdc_menu' shortcode in all versions up to, and including, 2.3. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes, specifically the 'text' and 'cat' attributes.… | |
| Aplazada | Alta (7.5) | 0.51% | — | Creatives Planet Greenly Theme AddonsAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly Theme Addons greenly-addons allows PHP Local File Inclusion.This issue affects Greenly Theme Addons: from n/a through < 8.2. | |
| Aplazada | Alta (7.5) | 0.51% | — | Creatives Planet GreenlyAI | 13/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Greenly greenly allows PHP Local File Inclusion.This issue affects Greenly: from n/a through <= 8.1. | |
| Aplazada | Media (6.1) | 0.29% | — | Plugin-planet Simple Ajax ChatAI | 12/3/2026 | 17/6/2026 | The Simple Ajax Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'c' parameter in versions up to, and including, 20260217 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Baja (2.1) | 0.43% | — | Planet Icg-2510AI | 8/3/2026 | 17/6/2026 | A vulnerability was determined in Planet ICG-2510 1.0_20250811. The impacted element is the function sub_40C8E4 of the file /usr/sbin/httpd of the component Language Package Configuration Handler. Executing a manipulation of the argument Language can lead to stack-based buffer overflow. The attack can be launched… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ancorathemes Green PlanetAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Green Planet green-planet allows PHP Local File Inclusion.This issue affects Green Planet: from n/a through <= 1.1.14. | |
| Aplazada | Media (5.3) | 0.34% | — | Plugin-planet Simple Ajax ChatAI | 23/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat simple-ajax-chat allows Retrieve Embedded Sensitive Data.This issue affects Simple Ajax Chat: from n/a through <= 20251121. | |
| Aplazada | Media (5.3) | 0.37% | — | Plugin-planet User Submitted PostsAI | 18/2/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 20260113. This is due to the `usp_get_submitted_category()` function accepting user-submitted category IDs from the POST body without validating… | |
| Aplazada | Alta (8.5) | 0.17% | — | Texassoft CyberplanetAI | 5/2/2026 | 17/6/2026 | TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and gain elevated system… | |
| Aplazada | Media (6.4) | 0.26% | — | Plugin-planet User Submitted PostsAI | 16/1/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (4.7) | 0.52% | 💥 Exploit | Plugin-planet User Submitted PostsAI | 24/12/2025 | 7/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Jeff Starr User Submitted Posts user-submitted-posts allows Phishing.This issue affects User Submitted Posts: from n/a through <= 20251121. | |
| Aplazada | Media (4.9) | 0.52% | — | Plugin-planet Simple Download CounterAI | 10/12/2025 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient path validation in the `simple_download_counter_parse_path()` function. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Analizada | Media (4.8) | 0.20% | — | Objectplanet Opinio | 2/12/2025 | 3/9/2026 | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which executes in the browsing context of any visitor accessing the compromised survey. | |
| Analizada | Baja (2.1) | 0.31% | — | Objectplanet Opinio | 2/12/2025 | 25/9/2026 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination. | |
| Analizada | Baja (2.3) | 0.18% | — | Objectplanet Opinio | 2/12/2025 | 25/9/2026 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then access such files without authentication. | |
| Aplazada | Alta (8.1) | 0.52% | — | Creatives Planet LeblixAI | 6/11/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Leblix leblix allows PHP Local File Inclusion.This issue affects Leblix: from n/a through <= 2.4. | |
| Modificada | Alta (8.8) | 4.3% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related… | |
| Modificada | Alta (8.8) | 4.3% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related… | |
| Modificada | Alta (8.8) | 4.6% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is related to the… | |
| Modificada | Alta (8.8) | 4.6% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is related to the `new_password`… | |
| Modificada | Alta (8.8) | 0.77% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is… | |
| Modificada | Alta (8.8) | 0.73% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is… |