Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.29% | — | Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log… | |
| Analizada | Media (5.4) | 0.45% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device. This vulnerability exists because of missing authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Alta (8.8) | 0.95% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol… | |
| Analizada | Alta (8.6) | 0.12% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of sensitive information within config only and full… | |
| Analizada | Media (5.5) | 0.76% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. This vulnerability is due to insufficient validation… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this… | |
| Analizada | Media (6.5) | 0.49% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of… | |
| Analizada | Media (5.9) | 0.30% | — | Cisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.… | |
| Aplazada | Media (4.8) | 0.37% | — | Metronic Admin Dashboard TemplateAI | 30/9/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Analizada | Baja (2.7) | 0.43% | — | Uncannyowl Uncanny Groups FOR Learndash | 25/9/2024 | 17/6/2026 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1. This makes it possible for authenticated attackers, with group leader-level access and… | |
| Analizada | Alta (7.2) | 1.2% | 💥 PoC | Uncannyowl Uncanny Groups FOR Learndash | 25/9/2024 | 17/6/2026 | The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to the plugin not properly restricting what users a group leader can edit. This makes it possible for authenticated attackers, with group leader-level access and above,… | |
| Analizada | Alta (8.8) | 0.71% | — | Buffercode Frontend Dashboard | 10/9/2024 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Aplazada | Alta (7.3) | 1.9% | 💥 Exploit | LightdashAI | 30/8/2024 | 17/6/2026 | Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF request when exported, via a POST request to /api/v1/dashboards//export.… | |
| Aplazada | Media (5.4) | 0.57% | — | LightdashAI | 30/8/2024 | 17/6/2026 | Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store… | |
| Analizada | Alta (8.8) | 0.21% | — | Naiches Dark Mode FOR WP Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3. | |
| Analizada | Baja (3.5) | 0.18% | — | Analytify - Google Analytics Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1. | |
| Aplazada | Media (6.1) | 0.26% | — | Opensearch DashboardsAIOpensearch SecurityAI | 23/8/2024 | 17/6/2026 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and… | |
| Aplazada | Media (4.2) | 0.17% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 16/8/2024 | 17/6/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download… | |
| Aplazada | Media (6.5) | 0.26% | — | Jeroensormani WP Dashboard NotesAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11. | |
| Aplazada | Alta (7.1) | 0.30% | — | Uncannyowl TIN Canny Reporting FOR LearndashAI | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Tin Canny Reporting for LearnDash allows Reflected XSS.This issue affects Tin Canny Reporting for LearnDash: from n/a through 4.3.0.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Uncannyowl Uncanny Toolkit PRO FOR LearndashAI | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Reflected XSS.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1. | |
| Aplazada | Media (5.9) | 0.27% | — | Webstix Admin Dashboard RSS FeedAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webstix Admin Dashboard RSS Feed allows Stored XSS.This issue affects Admin Dashboard RSS Feed: from n/a through 3.1. | |
| Aplazada | Media (5.4) | 0.45% | — | Learndash LMS ReportsAI | 9/7/2024 | 17/6/2026 | The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. wrld_set_configuration, wrld_exclude_settings_save, apply_time_tracking_settings, wp_ajax_wrld_gutenberg_block_visit, etc..) in all versions up to, and… |