Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Sharethis Dashboard FOR Google AnalyticsAI | 10/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ShareThis ShareThis Dashboard for Google Analytics googleanalytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through <= 3.2.3. | |
| Aplazada | Alta (7.1) | 0.21% | — | Newsboard Post AND RSS ScrollerAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NewsBoard Plugin NewsBoard Post and RSS Scroller newsboard allows Stored XSS.This issue affects NewsBoard Post and RSS Scroller: from n/a through <= 1.2.12. | |
| Aplazada | Media (5.5) | 0.17% | — | Samsung ClipboardserviceAI | 8/4/2025 | 17/6/2026 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (6.5) | 0.40% | — | Pgn4web Embed ChessboardAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pgn4web Embed Chessboard embed-chessboard allows Stored XSS.This issue affects Embed Chessboard: from n/a through <= 3.08.00. | |
| Aplazada | Media (6.5) | 0.40% | — | Morgan KAY Chamber Dashboard Business DirectoryAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11. | |
| Aplazada | Alta (8.1) | 0.84% | — | Hossein Material DashboardAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Hossein Material Dashboard material-dashboard allows PHP Local File Inclusion.This issue affects Material Dashboard: from n/a through <= 1.4.5. | |
| Aplazada | Media (5.3) | 0.34% | — | Pickplugins JOB Board ManagerAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Media (5.3) | 0.47% | — | Themeglow JobboardAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Media (4.9) | 0.56% | — | Themeglow JOB Board LightAI | 1/4/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in themeglow JobBoard Job listing job-board-light allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoard Job listing: from n/a through <= 1.2.8. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Hossein Material DashboardAI | 1/4/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Hossein Material Dashboard material-dashboard allows Authentication Bypass.This issue affects Material Dashboard: from n/a through <= 1.4.5. | |
| Modificada | Media (4.3) | 0.33% | — | Analytify - Google Analytics Dashboard | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.5.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Ultimate DashboardAI | 26/3/2025 | 17/6/2026 | The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_module_actions function in all versions up to, and including, 3.8.7. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.7) | 0.32% | — | 3dswym 3ddashboardAI3DS 3dexperienceAI | 17/3/2025 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session. | |
| Analizada | Media (5.3) | 0.28% | — | Sharethis Dashboard FOR Google Analytics | 14/3/2025 | 17/6/2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() function in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to disable all features. | |
| Aplazada | Media (4.3) | 0.17% | — | Muntasir Rahman Custom Dashboard PageAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Muntasir Rahman Custom Dashboard Page custom-dashboard-page allows Cross Site Request Forgery.This issue affects Custom Dashboard Page: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.38% | — | Bowo System DashboardAI | 25/2/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard system-dashboard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects System Dashboard: from n/a through <= 2.8.18. | |
| Aplazada | Alta (7.1) | 0.31% | — | Fastflow Fast Flow DashboardAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow fast-flow-dashboard allows Reflected XSS.This issue affects Fast Flow: from n/a through <= 1.2.16. | |
| Analizada | Media (5.4) | 0.31% | — | Covertnine C9 Admin Dashboard | 21/2/2025 | 17/6/2026 | The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Boardroom Limited Dividend Distribution TAX Election SystemAI | 18/2/2025 | 17/6/2026 | A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input. | |
| Modificada | Alta (8.8) | 0.33% | — | Analytify - Google Analytics Dashboard | 17/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.5.0. | |
| Aplazada | Alta (7.1) | 0.31% | — | Kvvaradha KV Compose Email From DashboardAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kvvaradha Kv Compose Email From Dashboard kv-send-email-from-admin allows Reflected XSS.This issue affects Kv Compose Email From Dashboard: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.31% | — | Mike Martel Live DashboardAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mike Martel Live Dashboard live-dashboard allows Reflected XSS.This issue affects Live Dashboard: from n/a through <= 0.3.3. | |
| Aplazada | Alta (8.4) | 0.24% | — | Intel Server Board S2600wfAIIntel Server Board S2600stAIIntel Server Board S2600bpAIIntel Server Board M50cypAI+1 | 12/2/2025 | 17/6/2026 | Heap-based buffer overflow in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow a privileged user to enable escalation of… | |
| Aplazada | Media (5.8) | 0.20% | — | Intel Server Board S2600wfAIIntel Server Board S2600stAIIntel Server Board S2600bpAIIntel Server Board M50cypAI+1 | 12/2/2025 | 17/6/2026 | Improper access control in BMC Firmware for the Intel(R) Server Board S2600WF, Intel(R) Server Board S2600ST, Intel(R) Server Board S2600BP, before version 02.01.0017 and Intel(R) Server Board M50CYP and Intel(R) Server Board D50TNP before version R01.01.0009 may allow an authenticated user to enable escalation of… | |
| Aplazada | Media (6.4) | 0.60% | 💥 PoC | Opensearch Dashboards-reportingAIOpensearchAI | 12/2/2025 | 17/6/2026 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer. |