Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.37% | — | Plugin-planet Dashboard Widgets Suite | 13/6/2024 | 17/6/2026 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Media (5.4) | 0.30% | — | Wpbakery Page Builder Clipboard Project Wpbakery Page Builder Clipboard | 13/6/2024 | 17/6/2026 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link attribute within the vc_single_image shortcode in all versions up to, and including, 7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.33% | — | Arwebdesign Dashboard To-do List | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.2.0. | |
| Modificada | Alta (8.8) | 0.20% | — | Analytify - Google Analytics Dashboard | 8/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3. | |
| Modificada | Media (6.3) | 0.35% | — | Kanboard | 6/6/2024 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to a project only get checked on the URL parameter project_id. If the user is authorized to add users to this project the… | |
| Aplazada | Baja (3.7) | 0.30% | — | Davidvongries Ultimate DashboardAI | 4/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate Dashboard: from n/a through 3.7.10. | |
| Aplazada | Media (5.4) | 0.43% | — | WP Discussion Board Discussion BoardAI | 4/6/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in WP Discussion Board Discussion Board allows Content Spoofing, Cross-Site Scripting (XSS).This issue affects Discussion Board: from n/a through 2.4.8. | |
| Aplazada | Media (6.5) | 0.67% | — | Wpfactory Download Plugins AND Themes From DashboardAI | 22/5/2024 | 17/6/2026 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server. | |
| Aplazada | Media (5.4) | 0.25% | — | 3DS 3ddashboardAI3dswymerAI | 17/5/2024 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code. | |
| Aplazada | Media (6.7) | 0.17% | — | Intel Onboard Video DriverAIIntel 62X ChipsetAI | 16/5/2024 | 17/6/2026 | Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.8) | 0.20% | — | Intel Server Board S2600bpAI | 16/5/2024 | 17/6/2026 | Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Media (6.1) | 0.41% | — | SIR Gnuboard | 14/5/2024 | 17/6/2026 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py. | |
| Modificada | Media (5.4) | 0.29% | — | Analytify - Google Analytics Dashboard | 2/5/2024 | 17/6/2026 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for… | |
| Modificada | Media (5.3) | 0.43% | — | Analytify - Google Analytics Dashboard | 2/5/2024 | 17/6/2026 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.20% | — | Wprepublic Hide Dashboard NotificationsAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Republic Hide Dashboard Notifications.This issue affects Hide Dashboard Notifications: from n/a through 1.2.3. | |
| Aplazada | Alta (7.5) | 0.68% | — | Buffercode Frontend DashboardAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2. | |
| Analizada | Media (5.5) | 0.22% | — | Dell Telemetry Dashboard | 24/4/2024 | 17/6/2026 | Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability to read sensitive proxy settings information. | |
| Aplazada | Media (4.3) | 0.20% | — | Dashboard TO DO ListAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Presstigers Simple JOB Board | 9/4/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to inject a PHP Object. If a POP chain is… | |
| Aplazada | Media (4.4) | 0.36% | — | Announce From THE DashboardAI | 4/4/2024 | 17/6/2026 | The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and… | |
| Analizada | Media (6.5) | 0.58% | — | Thingsboard | 3/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code of the component AdvancedFeature. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-259282 is… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco Nexus Dashboard Fabric Controller | 3/4/2024 | 17/6/2026 | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through… | |
| Analizada | Media (4.3) | 0.38% | — | Cisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user… | |
| Analizada | Media (4.3) | 0.41% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to learn cluster deployment information on an affected device. This vulnerability is due to improper access controls on a specific API endpoint. An attacker could exploit this vulnerability by sending queries to the API endpoint. A… | |
| Analizada | Media (6) | 0.17% | — | Cisco Nexus Dashboard | 3/4/2024 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard could allow an authenticated, local attacker with valid rescue-user credentials to elevate privileges to root on an affected device. This vulnerability is due to insufficient protections for a sensitive access token. An attacker could exploit this vulnerability by using this… |