Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.55%—Analytify - Google Analytics Dashboard13/12/202417/6/2026
Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0.
AnalizadaMedia (6.1)0.34%—Bowo System Dashboard10/12/202417/6/2026
The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.
AnalizadaMedia (4.9)2.1%💥 ExploitBowo System Dashboard10/12/202417/6/2026
The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server
ModificadaMedia (6.5)0.45%—Analytify - Google Analytics Dashboard9/12/202417/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3.
ModificadaMedia (4.3)0.37%—Analytify - Google Analytics Dashboard9/12/202417/6/2026
Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1.
ModificadaAlta (8.8)0.55%—Ultimatemember Jobboardwp9/12/202417/6/2026
Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job Board Listings and Submissions: from n/a through 1.2.2.
AnalizadaMedia (5.3)0.39%—Code-projects Admin Dashboard9/12/202417/6/2026
A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed…
AnalizadaMedia (6.9)0.83%—Fabian Online Notice Board5/12/202417/6/2026
A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated…
AnalizadaMedia (5.5)0.39%—Kanboard5/12/202417/6/2026
Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The…
AplazadaCrítica (9.8)0.65%—Eyecix Jobsearch WP JOB BoardAI28/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated…
AnalizadaMedia (6.1)0.47%—Ultimatemember Jobboardwp23/11/202417/6/2026
The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject…
AplazadaCrítica (9.8)0.77%—BlackboardAI21/11/20245/7/2026
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.
AplazadaMedia (6.5)0.33%—Duogeek Custom Dashboard WidgetAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0.
AplazadaMedia (4.3)0.22%—Automattic Crowdsignal DashboardAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through <= 3.1.3.
ModificadaMedia (5.4)0.24%—Maheshwaghmare Copy Anything TO Clipboard18/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency Copy Anything to Clipboard copy-the-code allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through <= 4.0.3.
AnalizadaAlta (8.7)0.14%—Intel Server Board M70klp2sb Firmware13/11/202417/6/2026
Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.1)0.19%—Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI13/11/202417/6/2026
Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel Server Board S2600st Family Bios AND Firmware UpdateAI13/11/202417/6/2026
Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)0.18%—Intel Server Board S2600bp Family Uefi FirmwareAI13/11/202417/6/2026
Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.2)0.94%—Kanboard11/11/202417/6/2026
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `settings` table.…
AnalizadaAlta (7.2)0.85%💥 PoCKanboard11/11/202417/6/2026
Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an…
AnalizadaAlta (8.8)0.77%—Cisco Nexus Dashboard Fabric Controller6/11/202417/6/2026
A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device.
AnalizadaCrítica (9.8)0.86%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the…
AnalizadaAlta (8.8)0.79%—Eyecix Jobsearch WP JOB Board6/11/202417/6/2026
The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload…
AnalizadaAlta (8.8)0.56%—Idrsdev Agile-board4/11/202417/6/2026
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.