Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.37% | — | Monsterinsights Google Analytics Dashboard | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Plugin-planet Dashboard Widget Suite | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions. | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Alta (7.2) | 1.3% | — | Pwsdashboard Personal Weather Station Dashboard | 25/4/2023 | 17/6/2026 | PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a… | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Media (4.8) | 0.37% | — | Announce From THE Dashboard Project Announce From THE Dashboard | 7/4/2023 | 17/6/2026 | Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions. | |
| Modificada | Media (5.3) | 0.44% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data… | |
| Modificada | Media (6.5) | 0.24% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data… | |
| Modificada | Media (5.3) | 0.24% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.61% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (8.8) | 0.73% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (7.8) | 6.5% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.40% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim… | |
| Modificada | Alta (8.8) | 0.88% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data… | |
| Modificada | Media (4.3) | 0.26% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client. | |
| Modificada | Media (4.3) | 0.25% | — | Dash10 Oauth Server | 20/3/2023 | 17/6/2026 | The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack. | |
| Modificada | Media (6.1) | 0.52% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An… | |
| Modificada | Alta (7.5) | 0.95% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of… | |
| Modificada | Alta (8.1) | 0.82% | — | Dash7-alliance Dash7 Alliance Protcol | 1/3/2023 | 17/6/2026 | The Sub-IoT implementation of the DASH 7 Alliance protocol has a vulnerability that can lead to an out-of-bounds write prior to implementation version 0.5.0. If the protocol has been compiled using default settings, this will only grant the attacker access to allocated but unused memory. However, if it was configured… | |
| Modificada | Media (6.1) | 0.40% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). | |
| Modificada | Media (6.1) | 0.37% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.) | |
| Modificada | Media (5.4) | 0.39% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2). | |
| Modificada | Crítica (9.8) | 1.6% | — | Dasherr Project Dasherr | 20/1/2023 | 17/6/2026 | erohtar/Dasherr is a dashboard for self-hosted services. In affected versions unrestricted file upload allows any unauthenticated user to execute arbitrary code on the server. The file /www/include/filesave.php allows for any file to uploaded to anywhere. If an attacker uploads a php file they can execute code on the… | |
| Modificada | Media (6.1) | 0.53% | — | Zenoss Dashboard | 1/1/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of the file ZenPacks/zenoss/Dashboard/browser/resources/js/defaultportlets.js. The manipulation of the argument HTMLString leads to cross site scripting. The attack can be… | |
| Modificada | Media (6.1) | 0.61% | — | Sterc Google Analytics Dashboard FOR Modx | 30/12/2022 | 17/6/2026 | A vulnerability was found in Sterc Google Analytics Dashboard for MODX up to 1.0.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget.analytics.tpl of the component Internal Search. The manipulation… |