Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.64% | — | Jenkins Deployment Dashboard | 30/6/2022 | 17/6/2026 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (6.1) | 0.65% | — | Yoast Google Analytics Dashboard | 24/6/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely. | |
| Modificada | Media (4.8) | 0.59% | — | Justsystems HPB Dashboard | 30/5/2022 | 17/6/2026 | The HPB Dashboard WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. | |
| Modificada | Media (5.4) | 1.1% | — | Uleak-security-dashboard Project Uleak-security-dashboard | 16/5/2022 | 17/6/2026 | The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks… | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Environment Dashboard | 15/3/2022 | 17/6/2026 | Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (5.4) | 0.82% | — | Jenkins Dashboard View | 15/3/2022 | 17/6/2026 | Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views. | |
| Modificada | Media (6.1) | 0.73% | — | HPE Oneview Global Dashboard | 24/2/2022 | 17/6/2026 | A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. | |
| Modificada | Media (6.1) | 0.56% | — | HPE Oneview Global Dashboard | 24/2/2022 | 17/6/2026 | A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. | |
| Modificada | Alta (7.5) | 2.2% | — | Camunda Min-dash | 21/1/2022 | 17/6/2026 | The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types. | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Apache Apisix Dashboard | 27/12/2021 | 17/6/2026 | In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Alta (8.8) | 1.0% | — | Redash | 24/11/2021 | 17/6/2026 | Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading data sources like JSON, CSV, or Excel is vulnerable to advanced methods of Server Side Request Forgery (SSRF). These vulnerabilities are only exploitable on installations where a URL-loading data… | |
| Modificada | Media (6.1) | 0.31% | — | Redash | 24/11/2021 | 17/6/2026 | Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google Login (via OAuth) incorrectly uses the `state` parameter to pass the next URL to redirect the user to after login. The `state` parameter should be used for a Cross-Site Request Forgery (CSRF) token,… | |
| Modificada | Media (6.5) | 8.1% | 💥 Exploit | Redash | 24/11/2021 | 17/6/2026 | Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is… | |
| Modificada | Alta (7.5) | 1.6% | — | Learndash | 1/11/2021 | 17/6/2026 | The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server | |
| Modificada | Media (6.1) | 0.83% | — | Sharethis Dashboard FOR Google Analytics | 30/8/2021 | 17/6/2026 | The ShareThis Dashboard for Google Analytics WordPress plugin before 2.5.2 does not sanitise or escape the 'ga_action' parameter in the stats view before outputting it back in an attribute when the plugin is connected to a Google Analytics account, leading to a reflected Cross-Site Scripting issue which will be… | |
| Modificada | Media (4.8) | 0.68% | — | Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard | 23/8/2021 | 17/6/2026 | The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled) | |
| Modificada | Crítica (9.8) | 1.3% | — | Ts-nodash Project Ts-nodash | 2/7/2021 | 17/6/2026 | All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input. | |
| Modificada | Media (5.5) | 0.23% | — | HPE Oneview Global Dashboard | 24/6/2021 | 17/6/2026 | A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32. | |
| Modificada | Alta (7.5) | 1.2% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser. | |
| Modificada | Alta (7.8) | 0.23% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user. | |
| Modificada | Media (5.4) | 0.54% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users. | |
| Modificada | Alta (8.8) | 1.3% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands. | |
| Modificada | Media (5.5) | 0.18% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information. | |
| Modificada | Media (5.5) | 0.15% | — | Zoll Defibrillator Dashboard | 16/6/2021 | 17/6/2026 | ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information. |