Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.57% | — | Nodered Node-red-dashboard | 8/10/2019 | 17/6/2026 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. | |
| Modificada | Media (6.1) | 0.92% | — | Wpfactory Download Plugins AND Themes From Dashboard | 7/10/2019 | 17/6/2026 | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues. | |
| Modificada | Media (5.9) | 1.5% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources… | |
| Modificada | Alta (7.5) | 0.66% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available. | |
| Modificada | Alta (7.2) | 1.7% | — | Trivetechnology Wp-stats-dashboard | 20/9/2019 | 17/6/2026 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Dashboard View | 12/9/2019 | 17/6/2026 | Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions. | |
| Modificada | Alta (8.8) | 0.67% | — | Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard | 16/8/2019 | 17/6/2026 | The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 1.5% | — | Glpi Dashboard Project Glpi Dashboard | 2/6/2019 | 17/6/2026 | Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh. | |
| Modificada | Media (5.8) | 1.6% | — | Wso2 Dashboard Server | 14/5/2019 | 17/6/2026 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF. | |
| Modificada | Media (4.8) | 1.0% | — | Wso2 Dashboard Server | 14/5/2019 | 17/6/2026 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Kubernetes Dashboard | 3/1/2019 | 17/6/2026 | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster. | |
| Modificada | Alta (7.5) | 3.0% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116. | |
| Modificada | Media (6.1) | 1.0% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | |
| Modificada | Crítica (9.8) | 5.6% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to… | |
| Modificada | Alta (7.8) | 0.36% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization,… | |
| Modificada | Alta (7.5) | 2.5% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose… | |
| Modificada | Alta (7.5) | 1.6% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to… | |
| Modificada | Crítica (9.8) | 3.7% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several stack-based buffer overflow vulnerabilities have been identified, which may allow an… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several untrusted pointer dereference vulnerabilities have been identified, which may allow an… |