Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.64%—Jenkins Deployment Dashboard30/6/202217/6/2026
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.
ModificadaMedia (6.1)0.65%—Yoast Google Analytics Dashboard24/6/202217/6/2026
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.
ModificadaMedia (4.8)0.59%—Justsystems HPB Dashboard30/5/202217/6/2026
The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
ModificadaMedia (5.4)1.1%—Uleak-security-dashboard Project Uleak-security-dashboard16/5/202217/6/2026
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks…
ModificadaMedia (5.4)0.82%—Jenkins Environment Dashboard15/3/202217/6/2026
Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.
ModificadaMedia (5.4)0.82%—Jenkins Dashboard View15/3/202217/6/2026
Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.
ModificadaMedia (6.1)0.73%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaMedia (6.1)0.56%—HPE Oneview Global Dashboard24/2/202217/6/2026
A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
ModificadaAlta (7.5)2.2%—Camunda Min-dash21/1/202217/6/2026
The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.
ModificadaCrítica (9.8)86%💥 ExploitApache Apisix Dashboard27/12/202117/6/2026
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the…
AnalizadaCrítica (10)100%⚠ Explotación activa💥 ExploitSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaAlta (8.8)1.0%—Redash24/11/202117/6/2026
Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on installations where a URL-loading data…
ModificadaMedia (6.1)0.31%—Redash24/11/202117/6/2026
Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token,…
ModificadaMedia (6.5)8.1%💥 ExploitRedash24/11/202117/6/2026
Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is…
ModificadaAlta (7.5)1.6%—Learndash1/11/202117/6/2026
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
ModificadaMedia (6.1)0.83%—Sharethis Dashboard FOR Google Analytics30/8/202117/6/2026
The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be…
ModificadaMedia (4.8)0.68%—Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard23/8/202117/6/2026
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)
ModificadaCrítica (9.8)1.3%—Ts-nodash Project Ts-nodash2/7/202117/6/2026
All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
ModificadaMedia (5.5)0.23%—HPE Oneview Global Dashboard24/6/202117/6/2026
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.
ModificadaAlta (7.5)1.2%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
ModificadaAlta (7.8)0.23%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
ModificadaMedia (5.4)0.54%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.
ModificadaAlta (8.8)1.3%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
ModificadaMedia (5.5)0.18%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
ModificadaMedia (5.5)0.15%—Zoll Defibrillator Dashboard16/6/202117/6/2026
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.