Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.14% | — | Victor Barkalov Custom Links ON Admin Dashboard ToolbarAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3. | |
| Analizada | Alta (7.3) | 1.3% | — | Netapp HCI Baseboard Management ControllerNetapp HCI H610s FirmwareNetapp HCI H610c FirmwareNetapp HCI H615c Firmware+4 | 5/2/2025 | 17/6/2026 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. | |
| Aplazada | Alta (7.1) | 0.31% | — | WpjobboardAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound WPJobBoard allows Reflected XSS. This issue affects WPJobBoard: from n/a through 5.10.1. | |
| Aplazada | Alta (7.1) | 0.32% | — | Pickplugins JOB Board ManagerAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows Reflected XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Modificada | Media (6.1) | 0.40% | — | Bowo System Dashboard | 30/1/2025 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (6.4) | 0.31% | — | Notice Board BY TowkirAI | 25/1/2025 | 17/6/2026 | The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-board' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.31% | — | Exactmetrics Google Analytics Dashboard FOR WPAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi ExactMetrics google-analytics-dashboard-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ExactMetrics: from n/a through <= 8.1.0. | |
| Aplazada | Media (5.4) | 0.19% | — | Pickplugins JOB Board ManagerAI | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affects Job Board Manager: from n/a through <= 2.1.59. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 24/1/2025 | 17/6/2026 | IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion. | |
| Aplazada | Alta (7.1) | 0.26% | — | Flx0 FLX Dashboard GroupsAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flx0 FLX Dashboard Groups flx-dashboard-groups allows Reflected XSS.This issue affects FLX Dashboard Groups: from n/a through <= 0.0.7. | |
| Aplazada | Media (5.4) | 0.48% | — | Chandrika Guntur Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8. | |
| Aplazada | Alta (7.1) | 0.20% | — | Pascal Casier Board ElectionAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pascal Casier Board Election board-election allows Stored XSS.This issue affects Board Election: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.4) | 0.34% | — | Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Alta (7.1) | 0.27% | — | Codebycarter WP Bulletin BoardAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codebycarter WP Bulletin Board wp-bulletin-board allows Reflected XSS.This issue affects WP Bulletin Board: from n/a through <= 1.1.4. | |
| Aplazada | Media (6.8) | 0.26% | — | Neat Board NFCAI | 9/1/2025 | 17/6/2026 | Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field | |
| Aplazada | Alta (7.1) | 0.32% | — | Kitae Park Mang Board WPAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kitae Park Mang Board WP mangboard allows Reflected XSS.This issue affects Mang Board WP: from n/a through <= 1.8.4. | |
| Aplazada | Crítica (10) | 0.53% | — | Themeglow Job-board-lightAI | 7/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through <= 1.2.6. | |
| Analizada | Crítica (9.8) | 0.39% | — | Analytify - Google Analytics Dashboard | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3. | |
| Aplazada | Alta (7.1) | 0.34% | — | Duogeek Custom Dashboard WidgetAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0. | |
| Modificada | Crítica (9.8) | 0.44% | — | Presstigers Simple JOB Board | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in PressTigers Simple Job Board simple-job-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Job Board: from n/a through <= 2.10.5. | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Mikeleembruggen Simple DashboardAI | 31/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0. | |
| Analizada | Media (6.5) | 0.52% | — | Kanboard | 19/12/2024 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard implements a cutom session handler (`app/Core/Session/SessionHandler.php`), to store the session data in a database. Therefore, when a… | |
| Aplazada | Media (5.3) | 0.55% | — | Pickplugins JOB Board ManagerAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Alta (7.1) | 0.21% | — | Crossfitatgg Leaderboard LiteAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in crossfitatgg LeaderBoard Plugin leaderboard-lite allows Stored XSS.This issue affects LeaderBoard Plugin: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.1) | 0.44% | — | Chuhpl Board Document ManagerAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cleveland Heights-University Heights Public Library Webdeveloper Board Document Manager from CHUHPL board-document-manager-from-chuhpl allows Reflected XSS.This issue affects Board Document Manager from CHUHPL: from… |