Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.30%—Cisco Nexus Dashboard Orchestrator2/10/202417/6/2026
This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.…
AplazadaAlta (7.5)0.56%—Minehyeong LIM MH BoardAI2/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.
AnalizadaMedia (6)0.79%—Thingsboard1/10/202417/6/2026
A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP RPC API. The manipulation leads to resource consumption. The attack can be launched remotely. The complexity of an attack is rather high. The…
AplazadaMedia (4.8)0.37%—Metronic Admin Dashboard TemplateAI30/9/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AnalizadaAlta (8.8)0.71%—Buffercode Frontend Dashboard10/9/202417/6/2026
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AnalizadaCrítica (9.8)0.52%—Eyecix Jobsearch WP JOB Board29/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.
AnalizadaAlta (8.8)0.21%—Naiches Dark Mode FOR WP Dashboard26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.
AnalizadaBaja (3.5)0.18%—Analytify - Google Analytics Dashboard26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.
ModificadaMedia (6.1)0.39%—SIR Gnuboard26/8/202417/6/2026
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
AnalizadaAlta (7.2)0.62%—Presstigers Simple JOB Board24/8/202417/6/2026
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP…
AplazadaMedia (6.1)0.26%—Opensearch DashboardsAIOpensearch SecurityAI23/8/202417/6/2026
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and…
AplazadaMedia (4.2)0.17%—Download Plugins AND Themes IN ZIP From DashboardAI16/8/202417/6/2026
The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download…
AnalizadaAlta (7.1)0.18%—Intel Server Board S2600st Firmware14/8/202417/6/2026
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.5)0.26%—Jeroensormani WP Dashboard NotesAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11.
AnalizadaAlta (8.8)0.29%—SIR Gnuboard12/8/202417/6/2026
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
AplazadaAlta (8.2)0.68%💥 PoCMicro-star International Z590 MotherboardAIMicro-star International Z490 MotherboardAIMicro-star International Z790 MotherboardAIMicro-star International B760 MotherboardAI+312/8/202417/6/2026
Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to 7D25v1H was discovered to contain a write-what-where condition in the in the SW handler for SMI 0xE3. Motherboard's with the following…
AplazadaAlta (7.5)0.74%—Neuq BoardAI29/7/202417/6/2026
Buffer Overflow vulnerability in host-host NEUQ_board v.1.0 allows a remote attacker to cause a denial of service via the password.h component.
AplazadaMedia (5.9)0.27%—Webstix Admin Dashboard RSS FeedAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webstix Admin Dashboard RSS Feed allows Stored XSS.This issue affects Admin Dashboard RSS Feed: from n/a through 3.1.
AplazadaMedia (6.5)0.25%—Pickplugins JOB Board ManagerAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Job Board Manager allows Stored XSS.This issue affects Job Board Manager: from n/a through 2.1.57.
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaMedia (6.1)0.25%—Virtosoftware Virto Kanban Board WEB PartAI25/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.
ModificadaMedia (4.3)0.34%—Wprepublic Hide Dashboard Notifications21/6/202417/6/2026
The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to…
AplazadaMedia (6.3)0.32%—Kingkong BoardAI14/6/202417/6/2026
Missing Authorization vulnerability in Bryan Lee Kingkong Board.This issue affects Kingkong Board: from n/a through 2.1.0.2.
ModificadaMedia (5.5)1.2%—Microsoft Telemetry Dashboard13/6/202417/6/2026
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information disclosure.
ModificadaMedia (6.1)0.37%—Plugin-planet Dashboard Widgets Suite13/6/202417/6/2026
The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…