Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to time records details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to calendar details using unauthorised internal identifiers. | |
| Modificada | Media (6.1) | 0.39% | — | Jeppesen Jetplanner | 21/5/2025 | 5/7/2026 | Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code. | |
| Aplazada | Alta (7.1) | 0.19% | — | Vsourz Digital WP MAP Route PlannerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital WP Map Route Planner wp-map-route-planner allows Cross Site Request Forgery.This issue affects WP Map Route Planner: from n/a through <= 1.0.0. | |
| Aplazada | Alta (7.1) | 0.39% | — | Abelony Events PlannerAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abelony Events Planner events-planner allows Reflected XSS.This issue affects Events Planner: from n/a through <= 1.3.10. | |
| Aplazada | Alta (7.1) | 0.37% | — | Sarah Lewis Content PlannerAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Lewis Content Planner content-planner allows Reflected XSS.This issue affects Content Planner: from n/a through <= 1.0. | |
| Analizada | Alta (7.5) | 0.46% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request. | |
| Analizada | Media (5.4) | 0.28% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Media (5.4) | 0.37% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Analizada | Media (5.3) | 0.41% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts. | |
| Analizada | Media (5.4) | 0.37% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Analizada | Alta (7.5) | 0.58% | — | Esoftplanner Esoft Planner | 20/11/2024 | 17/6/2026 | An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Aplazada | Media (5.3) | 0.40% | — | Progress PlannerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1. | |
| Analizada | Alta (7.5) | 0.99% | — | Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+1 | 27/8/2024 | 17/6/2026 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.… | |
| Modificada | Media (5.4) | 0.26% | — | Emilia Progress Planner | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Alta (8.8) | 1.2% | — | Wedding Planner Project Wedding Planner | 14/10/2022 | 17/6/2026 | Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 1.1% | — | Wedding Planner Project Wedding Planner | 14/10/2022 | 17/6/2026 | Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 1.1% | — | Wedding Planner Project Wedding Planner | 11/10/2022 | 17/6/2026 | Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php. | |
| Modificada | Alta (8.8) | 1.1% | — | Wedding Planner Project Wedding Planner | 11/10/2022 | 17/6/2026 | Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Wedding Planner Project Wedding Planner | 7/10/2022 | 17/6/2026 | Wedding Planner v1.0 is vulnerable to arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Wedding Planner Project Wedding Planner | 26/9/2022 | 17/6/2026 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php. |