Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.22% | — | Plugin-planet Simple Download Counter | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2. | |
| Modificada | Media (5.4) | 0.22% | — | Plugin-planet Theme Switcha | 22/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Picture-planet Gmbh Verowa ConnectAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Reflected XSS.This issue affects Verowa Connect: from n/a through <= 3.0.4. | |
| Aplazada | Alta (7.6) | 0.50% | — | Picture-planet Gmbh Verowa ConnectAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Blind SQL Injection.This issue affects Verowa Connect: from n/a through <= 3.0.5. | |
| Aplazada | Media (4.4) | 0.24% | — | Plugin-planet User Submitted PostsAI | 3/4/2025 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Alta (8.8) | 0.19% | — | Planetstudio Builder FOR Contact Form 7 | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forgery.This issue affects Builder for Contact Form 7 by Webconstruct: from n/a through <= 1.2.2. | |
| Aplazada | Media (6.5) | 0.44% | — | Plugin-planet Simple Download CounterAI | 1/3/2025 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including any local file… | |
| Aplazada | Alta (7.1) | 0.26% | — | Planetstudio Arca Payment GatewayAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio ArCa Payment Gateway arca-payment-gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through <= 1.3.1. | |
| Analizada | Media (4.9) | 0.34% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials. | |
| Analizada | Alta (8.8) | 0.28% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating… | |
| Analizada | Media (4.8) | 0.31% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack. | |
| Analizada | Crítica (9.8) | 0.58% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices. | |
| Analizada | Media (5.9) | 0.34% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c FirmwarePlanet Igs-5225-4up1t2s Firmware | 30/9/2024 | 17/6/2026 | The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them… | |
| Analizada | Alta (7.5) | 0.61% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service. | |
| Analizada | Media (4.9) | 0.30% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords. | |
| Analizada | Alta (7.5) | 0.18% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially. | |
| Analizada | Alta (7.5) | 0.55% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service. | |
| Analizada | Crítica (9.8) | 0.39% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to access the SNMPv1 service with read-write privileges. | |
| Analizada | Media (6.8) | 0.27% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via the serial console and use this credential to reset any user's password. | |
| Analizada | Alta (8.8) | 0.49% | — | Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware | 30/9/2024 | 17/6/2026 | Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with this credential and obtain a Linux root shell. | |
| Modificada | Alta (8.7) | 0.40% | — | Planetfitness Planet Fitness Workouts | 23/9/2024 | 17/6/2026 | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session tokens and sensitive information. Planet Fitness first addressed this vulnerability in version 9.8.12 (released on 2024-07-25) and more recently in… | |
| Analizada | Media (4.8) | 0.42% | — | Plugin-planet User Submitted Posts | 13/7/2024 | 17/6/2026 | The User Submitted Posts WordPress plugin before 20240516 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.37% | — | Plugin-planet Dashboard Widgets Suite | 13/6/2024 | 17/6/2026 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (5.4) | 0.33% | — | Plugin-planet Simple Ajax Chat | 4/6/2024 | 17/6/2026 | The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.4) | 0.50% | — | Planet Igs-4215-16t2sAI | 11/4/2024 | 17/6/2026 | Operating system command injection vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. An authenticated attacker could execute arbitrary code on the remote host by exploiting IP address functionality. |