Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.13% | — | Buffercode Frontend DashboardAI | 7/10/2026 | 7/10/2026 | The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, such as subscribers, to delete the Frontend Dashboard WordPress plugin before 3.0.0's configured profile and post form fields. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints | |
| Aplazada | Alta (7.5) | 0.46% | — | Viewsonic ViewboardAI | 5/10/2026 | 6/10/2026 | There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint | |
| Aplazada | Media (6.3) | 0.22% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in RegisterController::register that allows unauthenticated attackers to bypass the per-IP daily registration limit. Attackers can send many concurrent registration requests from one IP so all pass… | |
| Aplazada | Alta (7.1) | 0.31% | — | LaradashboardAI | 3/10/2026 | 6/10/2026 | LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers can query GET /api/settings or /api/settings/{option_name} to retrieve plaintext AI provider API keys, mail… | |
| Aplazada | Media (5.3) | 0.26% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving… | |
| Aplazada | Media (6.9) | 0.41% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for… | |
| Aplazada | Alta (8.6) | 0.49% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with role.edit can rename their role to Superadmin or grant user.login_as permissions to take over accounts and reach core upgrade… | |
| Aplazada | Media (6.3) | 0.31% | — | LaradashboardAI | 3/10/2026 | 5/10/2026 | LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON… | |
| Aplazada | Alta (7.1) | 0.20% | — | Nezha DashboardAI | 3/10/2026 | 5/10/2026 | Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin member can issue four notification API calls to permanently deadlock the alerting subsystem, then exhaust memory with blocking requests. | |
| Aplazada | Alta (7.2) | 0.24% | — | Mangboard Mang BoardAI | 2/10/2026 | 3/10/2026 | The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (6.3) | 0.25% | — | FluentboardsAI | 30/9/2026 | 30/9/2026 | Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions. | |
| Aplazada | Alta (7.1) | 0.32% | — | Nezha DashboardAI | 27/9/2026 | 28/9/2026 | Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mangboard Mang Board WPAI | 23/9/2026 | 23/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions. | |
| Aplazada | Media (5.3) | 0.21% | — | FluentboardsAI | 23/9/2026 | 23/9/2026 | The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators. | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.28% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.9) | 0.34% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Crítica (9.9) | 0.27% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Aplazada | Baja (3.8) | 0.26% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and… | |
| Aplazada | Baja (3.8) | 0.26% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators. | |
| Aplazada | Media (5.3) | 0.30% | — | KboardAI | 16/9/2026 | 17/9/2026 | The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their database records by iterating identifiers. | |
| Aplazada | Media (4.3) | 0.29% | — | FluentboardsAI | 16/9/2026 | 17/9/2026 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID. |