Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.42%—Linuxserver Heimdall Application Dashboard27/12/202217/6/2026
Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page. The stored XSS will be triggered in the "Application list" page.
ModificadaMedia (6.1)0.54%—Dash-live Project Dash-live25/12/202217/6/2026
A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function ready of the file static/js/media.js of the component DOM Node Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The name of the patch is…
ModificadaMedia (6.1)0.38%—HPE Oneview Global Dashboard12/12/202217/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).
ModificadaAlta (8.8)0.76%—Automattic Crowdsignal Dashboard17/11/202217/6/2026
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
ModificadaCrítica (9.8)0.98%—Pistar Pi-star Digital Voice Dashboard11/11/202217/6/2026
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
ModificadaAlta (8.8)0.33%—Analytify - Google Analytics Dashboard8/11/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
ModificadaMedia (6.1)0.65%—Eolink Apinto-dashboard1/11/202217/6/2026
A vulnerability was found in eolinker apinto-dashboard. It has been classified as problematic. Affected is an unknown function of the file /login. The manipulation of the argument callback leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (6.1)0.61%—Eolink Apinto-dashboard1/11/202217/6/2026
A vulnerability was found in eolinker apinto-dashboard and classified as problematic. This issue affects some unknown processing of the file /api/discoveries/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (6.1)0.47%—Eolink Apinto-dashboard1/11/202217/6/2026
A vulnerability was found in eolinker apinto-dashboard. It has been rated as problematic. This issue affects some unknown processing of the file /login. The manipulation of the argument callback leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (6.1)0.68%—Nodered Node-red-dashboard31/10/202217/6/2026
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.…
ModificadaAlta (7.5)3.9%💥 ExploitLinuxfoundation Dapr Dashboard3/10/202217/6/2026
Dapr Dashboard v0.1.0 through v0.10.0 is vulnerable to Incorrect Access Control that allows attackers to obtain sensitive data.
ModificadaMedia (6.1)0.63%—Automattic Crowdsignal Dashboard8/8/202217/6/2026
The Crowdsignal Dashboard WordPress plugin before 3.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.5)1.1%—Cisco Nexus Dashboard22/7/202217/6/2026
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with Administrator credentials could exploit this…
ModificadaMedia (6.7)0.22%—Cisco Nexus Dashboard22/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by…
ModificadaMedia (6.7)0.22%—Cisco Nexus Dashboard22/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by…
ModificadaMedia (6.7)0.21%—Cisco Nexus Dashboard22/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by…
ModificadaMedia (6.7)0.21%—Cisco Nexus Dashboard22/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to elevate privileges on an affected device. These vulnerabilities are due to insufficient input validation during CLI command execution on an affected device. An attacker could exploit these vulnerabilities by…
ModificadaAlta (8.8)0.60%—Cisco Nexus Dashboard21/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaAlta (7.4)0.55%—Cisco Nexus Dashboard21/7/202217/6/2026
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates are not validated when Cisco Nexus Dashboard is…
ModificadaCrítica (9.8)1.3%—Cisco Nexus Dashboard21/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaCrítica (9.8)1.6%—Cisco Nexus Dashboard21/7/202217/6/2026
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the Details section of this advisory.
ModificadaMedia (4.3)0.59%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (4.3)0.57%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
ModificadaMedia (4.3)0.59%—Jenkins Deployment Dashboard30/6/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.
ModificadaMedia (4.3)0.72%—Jenkins Deployment Dashboard30/6/202217/6/2026
A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Orbitaley — Vulnerabilidades