Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.42% | — | Linuxserver Heimdall Application Dashboard | 27/12/2022 | 17/6/2026 | Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page. | |
| Modificada | Media (6.1) | 0.54% | — | Dash-live Project Dash-live | 25/12/2022 | 17/6/2026 | A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is… | |
| Modificada | Media (6.1) | 0.38% | — | HPE Oneview Global Dashboard | 12/12/2022 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). | |
| Modificada | Alta (8.8) | 0.76% | — | Automattic Crowdsignal Dashboard | 17/11/2022 | 17/6/2026 | Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress. | |
| Modificada | Crítica (9.8) | 0.98% | — | Pistar Pi-star Digital Voice Dashboard | 11/11/2022 | 17/6/2026 | Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter. | |
| Modificada | Alta (8.8) | 0.33% | — | Analytify - Google Analytics Dashboard | 8/11/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress. | |
| Modificada | Media (6.1) | 0.65% | — | Eolink Apinto-dashboard | 1/11/2022 | 17/6/2026 | A vulnerability was found in eolinker apinto-dashboard. It has been classified as problematic. Affected is an unknown function of the file /login. The manipulation of the argument callback leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (6.1) | 0.61% | — | Eolink Apinto-dashboard | 1/11/2022 | 17/6/2026 | A vulnerability was found in eolinker apinto-dashboard and classified as problematic. This issue affects some unknown processing of the file /api/discoveries/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (6.1) | 0.47% | — | Eolink Apinto-dashboard | 1/11/2022 | 17/6/2026 | A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /login. The manipulation of the argument callback leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (6.1) | 0.68% | — | Nodered Node-red-dashboard | 31/10/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Linuxfoundation Dapr Dashboard | 3/10/2022 | 17/6/2026 | Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data. | |
| Modificada | Media (6.1) | 0.63% | — | Automattic Crowdsignal Dashboard | 8/8/2022 | 17/6/2026 | The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.22% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Media (6.7) | 0.21% | — | Cisco Nexus Dashboard | 22/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by… | |
| Modificada | Alta (8.8) | 0.60% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Alta (7.4) | 0.55% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is… | |
| Modificada | Crítica (9.8) | 1.3% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Crítica (9.8) | 1.6% | — | Cisco Nexus Dashboard | 21/7/2022 | 17/6/2026 | Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.57% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.59% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.72% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |