Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Plugin-planet User Submitted PostsAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr User Submitted Posts allows Stored XSS. This issue affects User Submitted Posts: from n/a through 20260810. | |
| Aplazada | Media (6.7) | 0.17% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device configuration file can recover the privileged-mode access password. | |
| Aplazada | Alta (7.5) | 0.58% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 26/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote administrator to cause a denial of service or potentially execute… | |
| Aplazada | Alta (7.7) | 0.71% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer allows a remote authenticated attacker to cause a denial of service or potentially… | |
| Aplazada | Alta (8.4) | 0.18% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable this debug mode to execute arbitrary code on the underlying operating system and… | |
| Aplazada | Alta (8.7) | 1.9% | — | Planet Igs-5225-8p2t4sAI | 18/9/2026 | 22/9/2026 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary… | |
| Aplazada | Alta (7.2) | 0.49% | — | Plugin-planet Simple Ajax ChatAI | 11/9/2026 | 11/9/2026 | The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Alta (8.8) | 0.51% | — | Plugin-planet Simple Ajax ChatAI | 2/9/2026 | 3/9/2026 | The Simple Ajax Chat WordPress plugin before 20260827 does not escape chat message content before rendering it, allowing unauthenticated users to inject arbitrary HTML attributes into the page and run scripts in the browser of anyone viewing the chat, including administrators. | |
| Pendiente de análisis | Media (6.9) | 0.57% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the web_sys_enablePasswd_post handler copies the… | |
| Pendiente de análisis | Media (6.9) | 0.60% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radKey_0, radDftParamKey, radName, and radIp POST parameters into fixed-size stack… | |
| Pendiente de análisis | Media (6.9) | 0.60% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers without length validation: web_vlan_membership_edit_dialog_post;… | |
| Pendiente de análisis | Media (6.9) | 0.56% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker can send a crafted request omitting the… | |
| Pendiente de análisis | Alta (8.7) | 0.71% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled… | |
| Pendiente de análisis | Alta (8.6) | 1.5% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A remote attacker with administrator web… | |
| Pendiente de análisis | Alta (8.6) | 0.94% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell metacharacters. A remote attacker with… | |
| Pendiente de análisis | Alta (8.6) | 1.5% | — | Planet Gs-4210-16p2sAI | 28/8/2026 | 8/9/2026 | PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A remote authenticated attacker can send a… | |
| Aplazada | Alta (8.5) | 0.14% | — | Planet9AI | 17/8/2026 | 3/9/2026 | A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application executable used by the Planet9 background service. The service runs with SYSTEM privileges, while the affected executable grants excessive permissions to non-administrative users. As a result, an… | |
| Aplazada | Media (6.6) | 0.41% | — | Acer Planet9AI | 17/8/2026 | 3/9/2026 | A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Planetary Computer | 7/8/2026 | 7/8/2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Ciena Navigator Network Control SuiteAICiena Manage Control PlanAICiena Blue PlanetAI | 14/7/2026 | 15/7/2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner… | |
| Aplazada | Media (4.2) | 0.22% | — | Plugin-planet User Submitted PostsAI | 1/7/2026 | 1/7/2026 | The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an admin-configured display template, leading to a Stored Cross-Site Scripting that can be triggered by unauthenticated users when a non-default display option is enabled. | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft Planetary Computer | 22/5/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.9) | 0.25% | — | Kaco BlueplanetAI | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All versions), blueplanet 125 TL3… | |
| Pendiente de análisis | Alta (7.2) | 0.19% | — | SMA Blueplanet 100 NX3 M8AISMA Blueplanet 100 TL3 Gen2AISMA Blueplanet 105 TL3AISMA Blueplanet 105 TL3 Gen2AI+26 | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 105 TL3 (All versions), blueplanet 105 TL3 GEN2 (All versions < V6.1.4.9), blueplanet 110 TL3 (All versions), blueplanet 125 NX3 M10 (All versions), blueplanet 125 TL3 (All… | |
| Aplazada | Alta (7.2) | 0.32% | — | Plugin-planet PrismaticAI | 16/4/2026 | 17/6/2026 | The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-shortcode in all versions up to, and including, 3.7.3. This is due to insufficient input sanitization and output escaping on user-supplied attributes within the 'prismatic_decode' function. This makes it… |