Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.21%—Webplanetsoft Inline Text PopupAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webplanetsoft Inline Text Popup inline-text-popup allows DOM-Based XSS.This issue affects Inline Text Popup: from n/a through <= 1.0.0.
ModificadaMedia (5.4)0.22%—Plugin-planet Simple Download Counter22/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Download Counter simple-download-counter allows Stored XSS.This issue affects Simple Download Counter: from n/a through <= 2.2.
ModificadaMedia (5.4)0.22%—Plugin-planet Theme Switcha22/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Theme Switcha theme-switcha allows Stored XSS.This issue affects Theme Switcha: from n/a through <= 3.4.
AplazadaAlta (7.1)0.29%—Picture-planet Gmbh Verowa ConnectAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Reflected XSS.This issue affects Verowa Connect: from n/a through <= 3.0.4.
AplazadaAlta (7.6)0.50%—Picture-planet Gmbh Verowa ConnectAI9/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Picture-Planet GmbH Verowa Connect verowa-connect allows Blind SQL Injection.This issue affects Verowa Connect: from n/a through <= 3.0.5.
AplazadaMedia (4.4)0.24%—Plugin-planet User Submitted PostsAI3/4/202517/6/2026
The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240319 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AnalizadaCrítica (9.8)0.69%—Invoiceplane28/3/202517/6/2026
InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerability in the upload_file method of the Upload controller.
ModificadaAlta (8.8)0.19%—Planetstudio Builder FOR Contact Form 711/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forgery.This issue affects Builder for Contact Form 7 by Webconstruct: from n/a through <= 1.2.2.
AplazadaMedia (6.5)0.44%—Plugin-planet Simple Download CounterAI1/3/202517/6/2026
The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.0 via the 'simple_download_counter_download_handler'. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including any local file…
AnalizadaMedia (5.4)0.27%—Plane6/1/202517/6/2026
Plane is an open-source project management tool. A cross-site scripting (XSS) vulnerability has been identified in Plane versions prior to 0.23. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing…
AnalizadaMedia (6.3)0.53%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known…
AnalizadaMedia (5.3)0.57%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1. It has been declared as critical. This vulnerability affects the function upload_file of the file /index.php/upload/upload_file/1/1. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.56%—Invoiceplane16/12/202417/6/2026
A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function download of the file invoices.php. The manipulation of the argument invoice leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AplazadaCrítica (9.1)0.36%—Oxide Control PlaneAI5/12/202417/6/2026
Oxide control plane software before 5 allows SSRF.
AplazadaAlta (7.1)0.26%—Planetstudio Arca Payment GatewayAI2/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio ArCa Payment Gateway arca-payment-gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through <= 1.3.1.
AnalizadaMedia (5.8)0.57%—Plane11/10/202417/6/2026
Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is fixed in 0.23.0.
AnalizadaMedia (4.9)0.34%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the file and obtain the credentials.
AnalizadaAlta (8.8)0.28%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a user into visiting a malicious website, allowing the attacker to impersonate the user and perform actions on their behalf, such as creating…
AnalizadaMedia (4.8)0.31%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to inject arbitrary JavaScript, leading to Stored XSS attack.
AnalizadaCrítica (9.8)0.58%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.
AnalizadaMedia (5.9)0.34%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c FirmwarePlanet Igs-5225-4up1t2s Firmware30/9/202417/6/2026
The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this service are encoded user passwords. Due to insufficient strength, unauthorized remote attackers who intercept the packets can directly crack them…
AnalizadaAlta (7.5)0.61%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing unauthenticated remote attackers to send crafted packets that can crash the service.
AnalizadaMedia (4.9)0.30%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read configuration files to obtain the hash values, and potentially crack them to retrieve the plaintext passwords.
AnalizadaAlta (7.5)0.18%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext SNMPv3 credentials potentially.
AnalizadaAlta (7.5)0.55%—Planet Gs-4210-24p2s FirmwarePlanet Gs-4210-24pl4c Firmware30/9/202417/6/2026
Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness to occupy connection slots and prevent legitimate users from accessing the SSH service.
Orbitaley — Vulnerabilidades