Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.1% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Alta (8.8) | 0.60% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.4) | 0.55% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is… | |
| Modificada | Crítica (9.8) | 1.3% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.57% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.72% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (6.1) | 0.65% | — | Yoast Google Analytics Dashboard | 24/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely. | |
| Modificada | Media (4.8) | 0.59% | — | Justsystems HPB Dashboard | 30/5/2022 | 17/6/2026 | The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Modificada | Media (5.4) | 1.1% | — | Uleak-security-dashboard Project Uleak-security-dashboard | 16/5/2022 | 17/6/2026 | The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks… | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Environment Dashboard | 15/3/2022 | 17/6/2026 | Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Dashboard View | 15/3/2022 | 17/6/2026 | Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views. | |
| Modificada | Media (6.1) | 0.73% | — | HPE Oneview Global Dashboard | 24/2/2022 | 17/6/2026 | A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. | |
| Modificada | Media (6.1) | 0.56% | — | HPE Oneview Global Dashboard | 24/2/2022 | 17/6/2026 | A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Apache Apisix Dashboard | 27/12/2021 | 17/6/2026 | In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.83% | — | Sharethis Dashboard FOR Google Analytics | 30/8/2021 | 17/6/2026 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be… | |
| Modificada | Media (4.8) | 0.68% | — | Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard | 23/8/2021 | 17/6/2026 | The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled) |