Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.55% | — | Analytify - Google Analytics Dashboard | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0. | |
| Analizada | Media (6.1) | 0.34% | — | Bowo System Dashboard | 10/12/2024 | 17/6/2026 | The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
| Analizada | Media (4.9) | 2.1% | 💥 Exploit | Bowo System Dashboard | 10/12/2024 | 17/6/2026 | The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal attacks an read arbitrary files on the server | |
| Modificada | Media (6.5) | 0.45% | — | Analytify - Google Analytics Dashboard | 9/12/2024 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Adnan Analytify wp-analytify.This issue affects Analytify: from n/a through <= 5.4.3. | |
| Modificada | Media (4.3) | 0.37% | — | Analytify - Google Analytics Dashboard | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1. | |
| Modificada | Alta (8.8) | 0.55% | — | Ultimatemember Jobboardwp | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job Board Listings and Submissions: from n/a through 1.2.2. | |
| Analizada | Media (5.3) | 0.39% | — | Code-projects Admin Dashboard | 9/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The manipulation of the argument username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.83% | — | Fabian Online Notice Board | 5/12/2024 | 17/6/2026 | A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file /registration.php of the component Profile Picture Handler. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated… | |
| Analizada | Media (5.5) | 0.39% | — | Kanboard | 5/12/2024 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, application_date_format,application_timezone and application_time_format allow arbirary user input which is reflected. The… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Eyecix Jobsearch WP JOB BoardAI | 28/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible for unauthenticated… | |
| Analizada | Media (6.1) | 0.47% | — | Ultimatemember Jobboardwp | 23/11/2024 | 17/6/2026 | The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Crítica (9.8) | 0.77% | — | BlackboardAI | 21/11/2024 | 5/7/2026 | An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file. | |
| Aplazada | Media (6.5) | 0.33% | — | Duogeek Custom Dashboard WidgetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0. | |
| Aplazada | Media (4.3) | 0.22% | — | Automattic Crowdsignal DashboardAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through <= 3.1.3. | |
| Modificada | Media (5.4) | 0.24% | — | Maheshwaghmare Copy Anything TO Clipboard | 18/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency Copy Anything to Clipboard copy-the-code allows Stored XSS.This issue affects Copy Anything to Clipboard: from n/a through <= 4.0.3. | |
| Analizada | Alta (8.7) | 0.14% | — | Intel Server Board M70klp2sb Firmware | 13/11/2024 | 17/6/2026 | Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.1) | 0.19% | — | Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI | 13/11/2024 | 17/6/2026 | Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Server Board S2600st Family Bios AND Firmware UpdateAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.7) | 0.18% | — | Intel Server Board S2600bp Family Uefi FirmwareAI | 13/11/2024 | 17/6/2026 | Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.94% | — | Kanboard | 11/11/2024 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `settings` table.… | |
| Analizada | Alta (7.2) | 0.85% | 💥 PoC | Kanboard | 11/11/2024 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files` SQLite db. Thus, an… | |
| Analizada | Alta (8.8) | 0.77% | — | Cisco Nexus Dashboard Fabric Controller | 6/11/2024 | 17/6/2026 | A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. | |
| Analizada | Crítica (9.8) | 0.86% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in all versions up to, and including, 2.6.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.79% | — | Eyecix Jobsearch WP JOB Board | 6/11/2024 | 17/6/2026 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in all versions up to, and including, 2.6.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload… | |
| Analizada | Alta (8.8) | 0.56% | — | Idrsdev Agile-board | 4/11/2024 | 17/6/2026 | A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. |