Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.43% | — | Buffercode Frontend DashboardAI | 13/5/2025 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s… | |
| Aplazada | Alta (8.8) | 0.45% | — | Buffercode Frontend DashboardAI | 13/5/2025 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By… | |
| Analizada | Baja (1.3) | 0.35% | — | Kanboard | 12/5/2025 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Versions 1.2.26 through 1.2.44 have a Stored Cross-Site Scripting (XSS) Vulnerability in the `name` parameter of the `http://localhost/?controller=ProjectCreationController&action=create` form. This vulnerability allows attackers to inject… | |
| Analizada | Media (6.5) | 0.36% | 💥 PoC | Thingsboard | 12/5/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Media (5.8) | 2.0% | 💥 Exploit | Pwsdashboard Personal Weather Station DashboardAI | 7/5/2025 | 17/6/2026 | Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Buffercode Frontend DashboardAI | 7/5/2025 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their… | |
| Analizada | Media (6.9) | 0.52% | — | Anujk305 Notice Board System | 5/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-reports-details.php?vid=2. The manipulation of the argument fromdate/tomdate leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (6.9) | 0.53% | — | Anujk305 Notice Board System | 29/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /category.php. The manipulation of the argument catname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.53% | 💥 PoC | Code-projects News Publishing Site Dashboard | 27/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be… | |
| Analizada | Media (5.3) | 0.53% | — | Code-projects News Publishing Site Dashboard | 27/4/2025 | 17/6/2026 | A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (8.1) | 0.51% | — | Eyecix Jobsearch WP JOB BoardAI | 25/4/2025 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.9.2. This is due to improper configurations in the 'jobsearch_xing_response_data_callback', 'set_access_tokes', and 'google_callback' functions. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Buffercode Frontend DashboardAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows SQL Injection.This issue affects Frontend Dashboard: from n/a through <= 2.2.5. | |
| Aplazada | Media (4.4) | 0.23% | — | Mang Board WPAI | 24/4/2025 | 17/6/2026 | The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the board_header and board_footer parameters in all versions up to, and including, 1.8.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Fluent BoardsAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBoards: from n/a through <= 1.47. | |
| Aplazada | Alta (7.1) | 0.15% | — | Swedish BOY Dashboard NotepadsAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.This issue affects Dashboard Notepads: from n/a through <= 1.2.1. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpseek Wordpress Dashboard TweeterAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2. | |
| Analizada | Baja (3.5) | 0.27% | — | Davidvongries Ultimate Dashboard | 17/4/2025 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.27% | — | Davidvongries Ultimate Dashboard | 17/4/2025 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Baja (3.5) | 0.27% | — | Davidvongries Ultimate Dashboard | 17/4/2025 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (5.3) | 0.52% | — | Cisco Nexus Dashboard | 16/4/2025 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of LDAP authentication requests. An attacker could exploit this vulnerability by sending authentication requests to an affected system. A… | |
| Aplazada | Crítica (9.6) | 0.24% | 💥 PoC | WpjobboardAI | 15/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Media (5.4) | 0.32% | — | WpjobboardAI | 15/4/2025 | 17/6/2026 | Path Traversal vulnerability in NotFound WPJobBoard allows Path Traversal. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Media (4.3) | 0.15% | — | WpjobboardAI | 15/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Cross Site Request Forgery. This issue affects WPJobBoard: from n/a through n/a. | |
| Aplazada | Alta (8.8) | 1.0% | — | Pickplugins JOB Board ManagerAI | 11/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PickPlugins Job Board Manager job-board-manager allows Object Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Alta (7.5) | 1.1% | — | Hossein Material DashboardAIPHPAI | 11/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5. |