Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.23%—HPE Oneview Global Dashboard24/6/202117/6/2026
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.
ModificadaAlta (7.5)1.2%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
ModificadaAlta (7.8)0.23%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
ModificadaMedia (5.4)0.54%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.
ModificadaAlta (8.8)1.3%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
ModificadaMedia (5.5)0.18%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
ModificadaMedia (5.5)0.15%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.
ModificadaMedia (5.3)2.7%—Apache Apisix Dashboard8/6/202117/6/2026
In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time,…
ModificadaMedia (5.4)73%—Jenkins Dashboard View11/5/202117/6/2026
Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.
ModificadaMedia (5.3)2.1%💥 ExploitThrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+1612/4/202117/6/2026
The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive…
ModificadaMedia (4.3)0.81%—Glpi-project Dashboard6/4/202117/6/2026
The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used.
ModificadaAlta (8.1)1.1%—Quadbase Espressdashboard15/3/202117/6/2026
An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads.
ModificadaMedia (4.3)0.45%—Quadbase Espressdashboard15/3/202117/6/2026
An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account.
ModificadaCrítica (9.8)46%—Docker Dashboard Project Docker Dashboard2/3/202117/6/2026
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
ModificadaAlta (7.5)19%💥 ExploitNodered Node-red-dashboard26/1/202117/6/2026
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
ModificadaAlta (7.8)0.43%—Westerndigital Dashboard12/12/202017/6/2026
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
ModificadaAlta (8.7)1.3%—Cogboard Red-dashboard9/12/202017/6/2026
Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code. By…
ModificadaAlta (8.8)1.3%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
ModificadaMedia (5.4)0.63%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an…
ModificadaAlta (7.2)2.1%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
ModificadaCrítica (9.9)3.3%—Openstack Blazar-dashboard16/10/202017/6/2026
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host…
ModificadaMedia (6.1)1.0%—Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory31/8/202017/6/2026
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
ModificadaMedia (6.5)0.73%—Prestashop Dashboard Products21/7/202017/6/2026
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.
ModificadaAlta (7.5)2.2%—HP Oneview Global Dashboard4/3/202017/6/2026
HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.
ModificadaAlta (7.8)0.45%—Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe19/2/202017/6/2026
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
Orbitaley — Vulnerabilidades