Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

81 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.25%—Boldworkplanner Bold Workplanner30/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers.
AnalizadaAlta (7.1)0.25%—Boldworkplanner Bold Workplanner30/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers.
AnalizadaAlta (7.1)0.25%—Boldworkplanner Bold Workplanner30/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to time records details using unauthorised internal identifiers.
AnalizadaAlta (7.1)0.25%—Boldworkplanner Bold Workplanner30/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to calendar details using unauthorised internal identifiers.
ModificadaMedia (6.1)0.39%—Jeppesen Jetplanner21/5/20255/7/2026
Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.
AplazadaAlta (7.1)0.19%—Vsourz Digital WP MAP Route PlannerAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital WP Map Route Planner wp-map-route-planner allows Cross Site Request Forgery.This issue affects WP Map Route Planner: from n/a through <= 1.0.0.
AplazadaAlta (7.1)0.39%—Abelony Events PlannerAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in abelony Events Planner events-planner allows Reflected XSS.This issue affects Events Planner: from n/a through <= 1.3.10.
AplazadaAlta (7.1)0.37%—Sarah Lewis Content PlannerAI22/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Lewis Content Planner content-planner allows Reflected XSS.This issue affects Content Planner: from n/a through <= 1.0.
AnalizadaAlta (7.5)0.46%—Esoftplanner Esoft Planner20/11/202417/6/2026
Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.
AnalizadaMedia (5.4)0.28%—Esoftplanner Esoft Planner20/11/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
AnalizadaMedia (5.4)0.37%—Esoftplanner Esoft Planner20/11/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AnalizadaMedia (5.3)0.41%—Esoftplanner Esoft Planner20/11/202417/6/2026
A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allows attackers to enumerate valid user e-mail accounts.
AnalizadaMedia (5.4)0.37%—Esoftplanner Esoft Planner20/11/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AnalizadaAlta (7.5)0.58%—Esoftplanner Esoft Planner20/11/202417/6/2026
An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
AplazadaMedia (5.3)0.40%—Progress PlannerAI1/11/202417/6/2026
Missing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1.
AnalizadaAlta (7.5)0.99%—Apollographql Apollo-routerApollographql Apollo GatewayApollographql Apollo Helms-charts RouterApollographql Apollo Query-planner+127/8/202417/6/2026
Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them to deliver autonomously and incrementally. Instances of @apollo/query-planner >=2.0.0 and <2.8.5 are impacted by a denial-of-service vulnerability.…
ModificadaMedia (5.4)0.26%—Emilia Progress Planner22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.2.
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (8.1)1.4%—QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+820/9/20234/8/2026
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and…
ModificadaAlta (8.8)1.2%—Wedding Planner Project Wedding Planner14/10/202217/6/2026
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)1.1%—Wedding Planner Project Wedding Planner14/10/202217/6/2026
Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (8.8)1.1%—Wedding Planner Project Wedding Planner11/10/202217/6/2026
Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.
ModificadaAlta (8.8)1.1%—Wedding Planner Project Wedding Planner11/10/202217/6/2026
Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.
ModificadaCrítica (9.8)1.5%—Wedding Planner Project Wedding Planner7/10/202217/6/2026
Wedding Planner v1.0 is vulnerable to arbitrary code execution.
ModificadaCrítica (9.8)1.1%—Wedding Planner Project Wedding Planner26/9/202217/6/2026
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.