Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.30% | — | Cisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.… | |
| Aplazada | Alta (7.5) | 0.56% | — | Minehyeong LIM MH BoardAI | 2/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1. | |
| Analizada | Media (6) | 0.79% | — | Thingsboard | 1/10/2024 | 17/6/2026 | A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP RPC API. The manipulation leads to resource consumption. The attack can be launched remotely. The complexity of an attack is rather high. The… | |
| Aplazada | Media (4.8) | 0.37% | — | Metronic Admin Dashboard TemplateAI | 30/9/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Analizada | Alta (8.8) | 0.71% | — | Buffercode Frontend Dashboard | 10/9/2024 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Analizada | Crítica (9.8) | 0.52% | — | Eyecix Jobsearch WP JOB Board | 29/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3. | |
| Analizada | Alta (8.8) | 0.21% | — | Naiches Dark Mode FOR WP Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3. | |
| Analizada | Baja (3.5) | 0.18% | — | Analytify - Google Analytics Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1. | |
| Modificada | Media (6.1) | 0.39% | — | SIR Gnuboard | 26/8/2024 | 17/6/2026 | There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path. | |
| Analizada | Alta (7.2) | 0.62% | — | Presstigers Simple JOB Board | 24/8/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP… | |
| Aplazada | Media (6.1) | 0.26% | — | Opensearch DashboardsAIOpensearch SecurityAI | 23/8/2024 | 17/6/2026 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and… | |
| Aplazada | Media (4.2) | 0.17% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 16/8/2024 | 17/6/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download… | |
| Analizada | Alta (7.1) | 0.18% | — | Intel Server Board S2600st Firmware | 14/8/2024 | 17/6/2026 | Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.26% | — | Jeroensormani WP Dashboard NotesAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11. | |
| Analizada | Alta (8.8) | 0.29% | — | SIR Gnuboard | 12/8/2024 | 17/6/2026 | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. | |
| Aplazada | Alta (8.2) | 0.68% | 💥 PoC | Micro-star International Z590 MotherboardAIMicro-star International Z490 MotherboardAIMicro-star International Z790 MotherboardAIMicro-star International B760 MotherboardAI+3 | 12/8/2024 | 17/6/2026 | Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3. Motherboard's with the following… | |
| Aplazada | Alta (7.5) | 0.74% | — | Neuq BoardAI | 29/7/2024 | 17/6/2026 | Buffer Overflow vulnerability in host-host NEUQ_board v.1.0 allows a remote attacker to cause a denial of service via the password.h component. | |
| Aplazada | Media (5.9) | 0.27% | — | Webstix Admin Dashboard RSS FeedAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webstix Admin Dashboard RSS Feed allows Stored XSS.This issue affects Admin Dashboard RSS Feed: from n/a through 3.1. | |
| Aplazada | Media (6.5) | 0.25% | — | Pickplugins JOB Board ManagerAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows Stored XSS.This issue affects Job Board Manager: from n/a through 2.1.57. | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Aplazada | Media (6.1) | 0.25% | — | Virtosoftware Virto Kanban Board WEB PartAI | 25/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS. | |
| Modificada | Media (4.3) | 0.34% | — | Wprepublic Hide Dashboard Notifications | 21/6/2024 | 17/6/2026 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to… | |
| Aplazada | Media (6.3) | 0.32% | — | Kingkong BoardAI | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2. | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Telemetry Dashboard | 13/6/2024 | 17/6/2026 | Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information disclosure. | |
| Modificada | Media (6.1) | 0.37% | — | Plugin-planet Dashboard Widgets Suite | 13/6/2024 | 17/6/2026 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… |