Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.81% | 💥 Exploit | Bowo System Dashboard | 20/3/2024 | 17/6/2026 | The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.22% | — | Automattic Crowdsignal Dashboard | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Media (4.3) | 0.30% | — | Mainwp Dashboard | 13/3/2024 | 17/6/2026 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.40% | — | Jeroensormani WP Dashboard Notes | 27/2/2024 | 17/6/2026 | The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and… | |
| Analizada | Alta (8.4) | 0.23% | — | TD Advanced Dashboard | 21/2/2024 | 17/6/2026 | The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information. | |
| Modificada | Media (6.1) | 0.35% | — | Automattic Crowdsignal Dashboard | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Stimulsoft Dashboards.php | 6/2/2024 | 9/7/2026 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. | |
| Modificada | Media (5.3) | 2.0% | 💥 Exploit | Learndash | 5/2/2024 | 17/6/2026 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes. | |
| Modificada | Media (5.3) | 2.4% | 💥 Exploit | Learndash | 5/2/2024 | 17/6/2026 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads. | |
| Modificada | Media (5.3) | 5.3% | 💥 Exploit | Learndash | 5/2/2024 | 17/6/2026 | The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions. | |
| Modificada | Media (6.1) | 0.83% | 💥 PoC | Stimulsoft Dashboard.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component. | |
| Modificada | Media (5.4) | 0.76% | 💥 PoC | Stimulsoft Dashboards.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |
| Modificada | Media (5.4) | 1.5% | 💥 Exploit | Plotly Dash | 2/2/2024 | 17/6/2026 | Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting… | |
| Modificada | Alta (8.8) | 0.19% | — | Custom Dashboard Widgets Project Custom Dashboard Widgets | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1. | |
| Modificada | Alta (8.2) | 0.46% | — | Flatlogic React Dashboard | 30/1/2024 | 17/6/2026 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. | |
| Modificada | Media (4.8) | 0.40% | — | Davidvongries Ultimate Dashboard | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11. | |
| Modificada | Alta (8.8) | 0.26% | — | Halgatewood Dashicons + Custom Post Types | 21/12/2023 | 17/6/2026 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2. | |
| Modificada | Media (4.9) | 0.55% | — | Mainwp Dashboard | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3. | |
| Modificada | Crítica (9.1) | 1.1% | — | Rmountjoy92 Dashmachine | 17/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 1.0% | — | Rmountjoy92 Dashmachine | 17/12/2023 | 17/6/2026 | A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to… | |
| Modificada | Media (5.4) | 0.41% | — | Realbigplugins Client Dash | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1. | |
| Modificada | Media (4.8) | 0.39% | — | Plugin-planet Dashboard Widget Suite | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1. | |
| Modificada | Media (6.1) | 0.40% | — | Deconf Clicky Analytics Dashboard | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. | |
| Modificada | Crítica (9.8) | 0.71% | — | Joomcode Jcdashboard | 14/12/2023 | 17/6/2026 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Deployment Dashboard | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs. |