Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.43% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.8) | 0.38% | — | Davidvongries Ultimate Dashboard | 22/11/2023 | 17/6/2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.8) | 0.35% | — | Properfraction Admin BAR & Dashboard Access Control | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions. | |
| Modificada | Media (4.3) | 0.50% | — | Dashy | 2/11/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Lissy93 Dashy 2.1.1. This affects an unknown part of the file /config-manager/save of the component Configuration Handler. The manipulation of the argument config leads to improper access controls. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.68% | — | Learndash | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LearnDash LearnDash LMS allows SQL Injection.This issue affects LearnDash LMS: from n/a through 4.5.3. | |
| Modificada | Media (6.5) | 0.52% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. | |
| Modificada | Media (6.1) | 0.33% | — | Extendwings Opcache Dashboard | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions. | |
| Modificada | Alta (8.8) | 0.59% | — | Wazuh-dashboardWazuh-kibana-app | 9/10/2023 | 17/6/2026 | Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their… | |
| Modificada | Alta (7.5) | 0.47% | — | Opendatahub Open Data HUB DashboardRedhat Openshift Data Science | 4/10/2023 | 17/6/2026 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret. | |
| Modificada | Alta (8.1) | 3.6% | — | Derrickgilland Pydash | 28/9/2023 | 17/6/2026 | This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and pydash.collections.invoke_map() accept dotted paths (Deep Path Strings) to target a nested Python object, relative to the original source object. These paths can be used to target internal class… | |
| Modificada | Media (4.8) | 0.37% | — | Suitedash Client Portal \ | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SuiteDash :: ONE Dashboard® Client Portal : SuiteDash Direct Login plugin <= 1.7.6 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | Open-falcon Dashboard | 11/8/2023 | 17/6/2026 | An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface. | |
| Modificada | Alta (7.5) | 0.80% | — | Dietpi-dashboard Project Dietpi-dashboard | 27/7/2023 | 17/6/2026 | DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be waiting for a handshake, and will stay this way indefinitely until a handshake… | |
| Modificada | Alta (8.8) | 2.2% | — | Learndash | 12/7/2023 | 17/6/2026 | The LearnDash LMS plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for attackers with with… | |
| Modificada | Crítica (9.8) | 1.6% | — | Robtopgames Geometry Dash | 11/7/2023 | 17/6/2026 | A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level. | |
| Modificada | Media (4.8) | 0.47% | — | Ultimate Dashboard Project Ultimate Dashboard | 19/6/2023 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Lightdash | 19/6/2023 | 17/6/2026 | packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used. | |
| Modificada | Alta (7.8) | 32% | — | Schneider-electric Igss Dashboard | 14/6/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. | |
| Modificada | Alta (8.8) | 0.27% | — | Uncannyowl Uncanny Toolkit FOR Learndash | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash plugin <= 3.6.4.1 versions. |