Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—Picture-planet Verowa ConnectAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Stored XSS.This issue affects Verowa Connect: from n/a through <= 3.2.3.
AplazadaCrítica (9.3)2.2%—Planet Technology Industrial Cellular GatewayAI17/9/202517/6/2026
Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the device.
AplazadaCrítica (9.3)0.83%—Planet Technology Industrial Cellular GatewayAI17/9/202517/6/2026
Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to manipulate the device via a specific functionality.
AplazadaBaja (1.9)0.14%—Rejseplanen APPAI29/8/202517/6/2026
A security vulnerability has been detected in Rejseplanen App up to 8.2.2. Affected is an unknown function of the file AndroidManifest.xml of the component de.hafas.android.rejseplanen. The manipulation leads to improper export of android application components. The attack needs to be performed locally. The exploit…
AplazadaMedia (5.4)0.21%—PlaneAI15/8/202517/6/2026
Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerability exists in the description_html field of Plane. This flaw allows an attacker to inject malicious JavaScript code that is stored and later executed in other users’ browsers. The description_html…
AplazadaCrítica (9.1)0.31%—PlaneAI13/8/202517/6/2026
Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
AplazadaMedia (4.8)0.22%—Planex Wrc-1167ghbk2-sAI24/6/202517/6/2026
WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who accessed WebGUI of the product.
AplazadaCrítica (9.8)0.48%—Ancorathem Kids PlanetAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in AncoraThemes Kids Planet kidsplanet allows Object Injection.This issue affects Kids Planet: from n/a through <= 2.2.14.
AnalizadaMedia (4.3)0.26%—Plane21/5/202517/6/2026
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scripting (XSS). Version…
AnalizadaMedia (6.5)0.29%—Planet Wgs-804hpt Firmware21/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ipv4Aclkey parameter in the web_acl_ipv4BasedAceAdd function.
AnalizadaMedia (6.5)0.29%—Planet Wgs-804hpt Firmware21/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ownekey parameter in the web_rmon_alarm_post_rmon_alarm function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bytftp_srvip parameter in the web_tool_upgradeManager_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radDftParamKey parameter in the web_radiusSrv_dftParam_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.
ModificadaCrítica (9.8)0.71%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.
AnalizadaCrítica (9.8)0.53%—Planet Wgs-804hpt Firmware20/5/202517/6/2026
FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.
AplazadaCrítica (9.3)1.2%—Planet Wgs-80hpt-v2AIPlanet Wgs-4215-8t2sAI24/4/202517/6/2026
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacker to execute OS commands on the host system.
Orbitaley — Vulnerabilidades