vciy

CVEs we hold for Planet

Records whose assigning authority named Planet as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9732EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Updateplanetshaker EmergencyWP – Dead Man's switch & legacy…
CVE-2026-81946PLANET IGS-5225-8P2T4S V1/V2 Weak Password Hashing via MD5 AlgorithmPLANET IGS-5225-8P2T4S V2
CVE-2026-81945PLANET IGS-5225-8P2T4S V1/V2 Admin Stack-Based Buffer Overflow via Web ServerPLANET IGS-5225-8P2T4S V2
CVE-2026-81944PLANET IGS-5225-8P2T4S V1/V2 Stack-Based Buffer Overflow via Web ServerPLANET IGS-5225-8P2T4S V2
CVE-2026-81943PLANET IGS-5225-8P2T4S V1/V2 Debug Mode RCEPLANET IGS-5225-8P2T4S V2
CVE-2026-81942PLANET IGS-5225-8P2T4S V1/V2 OS Command Injection via Web ServerPLANET IGS-5225-8P2T4S V2
CVE-2026-77218PLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Credential HandlersPLANET GS-4210-16P2S V3
CVE-2026-77217PLANET GS-4210-16P2S V3 Stack Buffer Overflow and NULL Pointer Dereference via dispatcher.cgi RADIUS HandlersPLANET GS-4210-16P2S V3
CVE-2026-75126PLANET GS-4210-16P2S V3 Stack Buffer Overflow via dispatcher.cgi Standard HandlersPLANET GS-4210-16P2S V3
CVE-2026-75125PLANET GS-4210-16P2S V3 Null Pointer Dereference DoS via dispatcher.cgi web_poe_alive_rmtip_postPLANET GS-4210-16P2S V3
CVE-2026-75124PLANET GS-4210-16P2S V3 Memory Corruption via dispatcher.cgi _readHttpParamPLANET GS-4210-16P2S V3
CVE-2026-75123PLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_smtp_test_postPLANET GS-4210-16P2S V3
CVE-2026-75122PLANET GS-4210-16P2S V3 Command Injection via httpuploadcert.cgiPLANET GS-4210-16P2S V3
CVE-2026-75121PLANET GS-4210-16P2S V3 Command Injection via dispatcher.cgi web_vlan_membership_edit_dialog_postPLANET GS-4210-16P2S V3
CVE-2026-3697Planet ICG-2510 Language Package Configuration httpd sub_40C8E4 stack-based overflowPlanet ICG-2510
CVE-2025-9972Planet Technology|Industrial Cellular Gateway - OS Command InjectionPlanet Technology ICG-2510W-LTE (EU/US)
CVE-2025-9971Planet Technology|Industrial Cellular Gateway - Missing AuthenticationPlanet Technology ICG-2510W-LTE (EU/US)
CVE-2025-8777planetcalc <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via language Parameterplanetcalc
CVE-2025-54406no title heldPlanet WGR-500
CVE-2025-54405no title heldPlanet WGR-500
CVE-2025-54404no title heldPlanet WGR-500
CVE-2025-54403no title heldPlanet WGR-500
CVE-2025-54402no title heldPlanet WGR-500
CVE-2025-54401no title heldPlanet WGR-500
CVE-2025-54400no title heldPlanet WGR-500
CVE-2025-54399no title heldPlanet WGR-500
CVE-2025-48826no title heldPlanet WGR-500
CVE-2025-46275Planet Technology Network Products Missing Authentication for Critical FunctionPlanet Technology WGS-4215-8T2S
CVE-2025-46274Planet Technology Network Products Use of Hard-coded CredentialsPlanet Technology UNI-NMS-Lite
CVE-2025-46273Planet Technology Network Products Use of Hard-coded CredentialsPlanet Technology UNI-NMS-Lite
CVE-2025-46272Planet Technology Network Products OS Command InjectionPlanet Technology WGS-4215-8T2S
CVE-2025-46271Planet Technology Network Products OS Command InjectionPlanet Technology UNI-NMS-Lite
CVE-2025-28864WordPress Builder for Contact Form 7 by Webconstruct plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) vulnerabilityplanetstudio Builder for Contact Form 7 by Webconstruct
CVE-2024-8459PLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwordsPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8458PLANET Technology switch devices - Cross-site Request ForgeryPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8457PLANET Technology switch devices - Stored cross-site scripting (XSS) in the User ManagementPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8456PLANET Technology switch devices - Missing Authentication for multiple HTTP routesPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8455PLANET Technology switch devices - Swctrl service exchanges weakly encoded passwordsPLANET Technology IGS-5225-4UP1T2S hardware 1.0
CVE-2024-8454PLANET Technology switch devices - Swctrl service DoS attackPLANET Technology IGS-5225-4UP1T2S hardware 1.0
CVE-2024-8453PLANET Technology switch devices - Weak hash for users' passwordsPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8452PLANET Technology switch devices - Insecure hash functions used for SNMPv3 credentialsPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8451PLANET Technology switch devices - SSH server DoS attackPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8450PLANET Technology switch devices - Hard-coded SNMPv1 read-write community stringPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8449PLANET Technology switch devices - Local users' passwords recovery through hard-coded credentialsPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-8448PLANET Technology switch devices - Remote privilege escalation using hard-coded credentialsPLANET Technology GS-4210-24P2S hardware 3.0
CVE-2024-53759WordPress ArCa Payment Gateway plugin <= 1.3.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerabilityPlanet Studio ArCa Payment Gateway
CVE-2024-52558Planet Technology Planet WGS-804HPT Integer UnderflowPlanet WGS-804HPT
CVE-2024-52320Planet Technology Planet WGS-804HPT Command InjectionPlanet WGS-804HPT
CVE-2024-48871Planet Technology Planet WGS-804HPT Stack-based Buffer OverflowPlanet WGS-804HPT
CVE-2024-43201Planet Fitness Workouts mobile apps do not properly validate TLS certificatesPlanet Fitness Workouts
CVE-2024-2742OS Command Injection in Planet IGS-4215-16T2SPlanet IGS-4215-16T2S
CVE-2024-2741Cross-Site Request Forgery in Planet IGS-4215-16T2SPlanet IGS-4215-16T2S
CVE-2024-2740Exposure of Sensitive Information to an Unauthorized Actor in Planet IGS-4215-16T2SPlanet IGS-4215-16T2S
CVE-2023-32303Planet's secret file is created with excessive permissionsplanetlabs planet-client-python
CVE-2015-10129planet-freo auth.inc.php comparisonn/a planet-freo

55 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.