Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.81%💥 ExploitBowo System Dashboard20/3/202417/6/2026
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
ModificadaAlta (8.8)0.22%—Automattic Crowdsignal Dashboard16/3/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
ModificadaMedia (4.3)0.30%—Mainwp Dashboard13/3/202417/6/2026
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated…
AnalizadaMedia (4.3)0.40%—Jeroensormani WP Dashboard Notes27/2/202417/6/2026
The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and…
AnalizadaAlta (8.4)0.23%—TD Advanced Dashboard21/2/202417/6/2026
The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information.
ModificadaMedia (6.1)0.35%—Automattic Crowdsignal Dashboard10/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
ModificadaCrítica (9.8)2.0%💥 PoCStimulsoft Dashboards.php6/2/20249/7/2026
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
ModificadaMedia (5.3)2.0%💥 ExploitLearndash5/2/202417/6/2026
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via API. This makes it possible for unauthenticated attackers to obtain access to quizzes.
ModificadaMedia (5.3)2.4%💥 ExploitLearndash5/2/202417/6/2026
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.1 via direct file access due to insufficient protection of uploaded assignments. This makes it possible for unauthenticated attackers to obtain those uploads.
ModificadaMedia (5.3)5.3%💥 ExploitLearndash5/2/202417/6/2026
The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.10.2 via API. This makes it possible for unauthenticated attackers to obtain access to quiz questions.
ModificadaMedia (6.1)0.83%💥 PoCStimulsoft Dashboard.js5/2/20249/7/2026
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
ModificadaMedia (5.4)0.76%💥 PoCStimulsoft Dashboards.js5/2/20249/7/2026
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.
ModificadaMedia (5.4)1.5%💥 ExploitPlotly Dash2/2/202417/6/2026
Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting…
ModificadaAlta (8.8)0.19%—Custom Dashboard Widgets Project Custom Dashboard Widgets31/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.
ModificadaAlta (8.2)0.46%—Flatlogic React Dashboard30/1/202417/6/2026
react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.
ModificadaMedia (4.8)0.40%—Davidvongries Ultimate Dashboard21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.
ModificadaAlta (8.8)0.26%—Halgatewood Dashicons + Custom Post Types21/12/202317/6/2026
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + Custom Post Types: from n/a through 1.0.2.
ModificadaMedia (4.9)0.55%—Mainwp Dashboard20/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3.
ModificadaCrítica (9.1)1.1%—Rmountjoy92 Dashmachine17/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)1.0%—Rmountjoy92 Dashmachine17/12/202317/6/2026
A vulnerability classified as problematic was found in rmountjoy92 DashMachine 0.5-4. Affected by this vulnerability is an unknown functionality of the file /settings/save_config of the component Config Handler. The manipulation of the argument value_template leads to code injection. The exploit has been disclosed to…
ModificadaMedia (5.4)0.41%—Realbigplugins Client Dash15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1.
ModificadaMedia (4.8)0.39%—Plugin-planet Dashboard Widget Suite14/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
ModificadaMedia (6.1)0.40%—Deconf Clicky Analytics Dashboard14/12/202317/6/2026
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
ModificadaCrítica (9.8)0.71%—Joomcode Jcdashboard14/12/202317/6/2026
Unauthenticated LFI/SSRF in JCDashboards component for Joomla.
ModificadaMedia (4.3)0.35%—Jenkins Deployment Dashboard13/12/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
Orbitaley — Vulnerabilidades