Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.77% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is… | |
| Modificada | Alta (8.8) | 6.9% | — | Planet Wgr-500 Firmware | 7/10/2025 | 17/6/2026 | A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. An attacker can send a series of HTTP requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.73% | — | Planet Wgr-500 Firmware | 7/10/2025 | 30/9/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is… | |
| Aplazada | Media (6.4) | 0.23% | — | PlanetcalcAI | 30/9/2025 | 17/6/2026 | The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.21% | — | Picture-planet Verowa ConnectAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Stored XSS.This issue affects Verowa Connect: from n/a through <= 3.2.3. | |
| Aplazada | Crítica (9.3) | 2.2% | — | Planet Technology Industrial Cellular GatewayAI | 17/9/2025 | 17/6/2026 | Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Planet Technology Industrial Cellular GatewayAI | 17/9/2025 | 17/6/2026 | Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Ancorathem Kids PlanetAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n/a through <= 2.2.14. | |
| Analizada | Media (6.5) | 0.29% | — | Planet Wgs-804hpt Firmware | 21/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function. | |
| Analizada | Media (6.5) | 0.29% | — | Planet Wgs-804hpt Firmware | 21/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function. | |
| Modificada | Crítica (9.8) | 0.71% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function. | |
| Analizada | Crítica (9.8) | 0.53% | — | Planet Wgs-804hpt Firmware | 20/5/2025 | 17/6/2026 | FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function. | |
| Aplazada | Crítica (9.3) | 1.2% | — | Planet Wgs-80hpt-v2AIPlanet Wgs-4215-8t2sAI | 24/4/2025 | 17/6/2026 | WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system. | |
| Aplazada | Media (6.5) | 0.21% | — | Webplanetsoft Inline Text PopupAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inline Text Popup inline-text-popup allows DOM-Based XSS.This issue affects Inline Text Popup: from n/a through <= 1.0.0. |