Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.23% | — | HPE Oneview Global Dashboard | 24/6/2021 | 17/6/2026 | A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32. | |
| Modificada | Alta (7.5) | 1.2% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser. | |
| Modificada | Alta (7.8) | 0.23% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user. | |
| Modificada | Media (5.4) | 0.54% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users. | |
| Modificada | Alta (8.8) | 1.3% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands. | |
| Modificada | Media (5.5) | 0.18% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information. | |
| Modificada | Media (5.5) | 0.15% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information. | |
| Modificada | Media (5.3) | 2.7% | — | Apache Apisix Dashboard | 8/6/2021 | 17/6/2026 | In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time,… | |
| Modificada | Media (5.4) | 73% | — | Jenkins Dashboard View | 11/5/2021 | 17/6/2026 | Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Media (4.3) | 0.81% | — | Glpi-project Dashboard | 6/4/2021 | 17/6/2026 | The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used. | |
| Modificada | Alta (8.1) | 1.1% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads. | |
| Modificada | Media (4.3) | 0.45% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account. | |
| Modificada | Crítica (9.8) | 46% | — | Docker Dashboard Project Docker Dashboard | 2/3/2021 | 17/6/2026 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Nodered Node-red-dashboard | 26/1/2021 | 17/6/2026 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | |
| Modificada | Alta (7.8) | 0.43% | — | Westerndigital Dashboard | 12/12/2020 | 17/6/2026 | Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. | |
| Modificada | Alta (8.7) | 1.3% | — | Cogboard Red-dashboard | 9/12/2020 | 17/6/2026 | Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code. By… | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level. | |
| Modificada | Media (5.4) | 0.63% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an… | |
| Modificada | Alta (7.2) | 2.1% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage. | |
| Modificada | Crítica (9.9) | 3.3% | — | Openstack Blazar-dashboard | 16/10/2020 | 17/6/2026 | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host… | |
| Modificada | Media (6.1) | 1.0% | — | Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory | 31/8/2020 | 17/6/2026 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. | |
| Modificada | Media (6.5) | 0.73% | — | Prestashop Dashboard Products | 21/7/2020 | 17/6/2026 | In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0. | |
| Modificada | Alta (7.5) | 2.2% | — | HP Oneview Global Dashboard | 4/3/2020 | 17/6/2026 | HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. |