Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | Zju-fast-lab Ego-planner-v2AI | 11/9/2026 | 22/9/2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic | |
| Aplazada | Alta (7.5) | 0.61% | — | Ego-plannerAI | 10/9/2026 | 22/9/2026 | An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp | |
| Aplazada | Alta (7.5) | 0.61% | — | Zju-fast-lab Ego-planner-v2AI | 10/9/2026 | 22/9/2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component | |
| Aplazada | Media (4) | 0.18% | — | Zju-fast-lab Ego-planner-v2AI | 10/9/2026 | 22/9/2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback() | |
| Aplazada | Crítica (9.1) | 0.63% | — | Zju-fast-lab Ego-planner-v2AI | 10/9/2026 | 22/9/2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline | |
| Pendiente de análisis | Media (6.3) | 0.35% | — | Migration-plannerAI | 14/8/2026 | 14/8/2026 | A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the… | |
| Aplazada | Media (4.3) | 0.42% | — | Reviews AND Rating DocplannerAI | 24/6/2026 | 25/6/2026 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomla Calendar Planner | 19/6/2026 | 19/8/2026 | Joomla! Component Calendar Planner 1.0.1 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the category_id parameter. Attackers can send GET requests to the events view with malicious SQL code in the category_id parameter to extract sensitive database… | |
| Analizada | Media (5.4) | 0.34% | — | Kubev2v Migration Planner UI | 10/6/2026 | 17/6/2026 | A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browser session. This… | |
| Aplazada | Media (5.9) | 0.24% | — | Emilia Progress PlannerAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0. | |
| Analizada | Alta (8.8) | 0.25% | — | Cipplanner Cipace | 11/2/2026 | 17/6/2026 | Vulnerabilities in the My Account and User Management components in CIPPlanner CIPAce before 9.17 allows attackers to escalate their access levels. A low-privileged authenticated user can gain access to other people's accounts by tampering with the client's user id to change their account information. A low-privileged… | |
| Analizada | Alta (7.5) | 0.25% | — | Cipplanner Cipace | 11/2/2026 | 17/6/2026 | Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended… | |
| Analizada | Alta (8.8) | 0.31% | — | Cipplanner Cipace | 11/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerabilities exist in the rich text editor and document manage components in CIPPlanner CIPAce before 9.17. An authorized user can upload executable files when inserting images in the rich text editor, and upload executable files when uploading files on the document… | |
| Analizada | Media (4.3) | 0.26% | — | Cipplanner Cipace | 11/2/2026 | 17/6/2026 | A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured to allow login with internal accounts, an attacker can possibly obtain full authentication if the secret in a… | |
| Aplazada | Media (4.4) | 0.20% | — | Weekly PlannerAI | 5/12/2025 | 17/6/2026 | The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (5.3) | 0.27% | — | Shelf PlannerAI | 11/11/2025 | 17/6/2026 | The Shelf Planner plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints in all versions up to, and including, 2.8.1. This makes it possible for unauthenticated attackers to modify several of the plugin's settings like the ServerKey and… | |
| Aplazada | Media (5.3) | 0.31% | — | Shelf PlannerAI | 11/11/2025 | 30/9/2026 | The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed log files. | |
| Aplazada | Alta (8.8) | 0.48% | — | Progress PlannerAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a through <= 1.8.0. | |
| Analizada | Alta (7.1) | 0.32% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the list of permissions using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.35% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a misuse of the general enquiry web service. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic employee details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to the dates of the current contract details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to planning counter details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to functional contract details using unauthorised internal identifiers. | |
| Analizada | Alta (7.1) | 0.25% | — | Boldworkplanner Bold Workplanner | 30/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), consisting of a lack of adequate validation of user input, allowing an authenticated user to access to basic contract details using unauthorised internal identifiers. |