Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.26% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the… | |
| Aplazada | Alta (7.1) | 0.35% | — | Kanbanwp Kanban BoardsAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Aplazada | Alta (7.1) | 0.42% | — | Hometory Mang Board WPAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Reflected XSS.This issue affects Mang Board WP: from n/a through 1.8.0. | |
| Modificada | Media (6.1) | 0.37% | — | Wpjobboard Jobeleon | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPJobBoard Jobeleon Theme allows Reflected XSS.This issue affects Jobeleon Theme: from n/a through 1.9.1. | |
| Aplazada | Media (6.5) | 0.36% | — | Buffercode Frontend DashboardAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vinoth06. Frontend Dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through 2.2.1. | |
| Analizada | Media (5.3) | 0.58% | — | Remyandrade Todo List IN Kanban Board | 27/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. Affected by this issue is some unknown functionality of the component Add ToDo. The manipulation of the argument Todo leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.82% | — | Remyandrade Todo List IN Kanban Board | 27/3/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-todo.php. The manipulation of the argument list leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Aplazada | Media (5.4) | 0.46% | — | Sharethis Dashboard FOR Google AnalyticsAI | 25/3/2024 | 17/6/2026 | Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4. | |
| Analizada | Media (5.4) | 0.81% | 💥 Exploit | Bowo System Dashboard | 20/3/2024 | 17/6/2026 | The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks | |
| Analizada | Media (6.1) | 0.53% | — | SIR Gnuboard | 16/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter. | |
| Modificada | Alta (8.8) | 0.22% | — | Automattic Crowdsignal Dashboard | 16/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Media (4.3) | 0.30% | — | Mainwp Dashboard | 13/3/2024 | 17/6/2026 | The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.0.1. This is due to missing or incorrect nonce validation on the 'posting_bulk' function. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.40% | — | Jeroensormani WP Dashboard Notes | 27/2/2024 | 17/6/2026 | The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and… | |
| Analizada | Alta (7.5) | 0.60% | — | Eyecix Jobsearch WP JOB Board | 27/2/2024 | 17/6/2026 | The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server | |
| Analizada | Alta (7.5) | 0.55% | — | Eyecix Jobsearch WP JOB Board | 27/2/2024 | 17/6/2026 | The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address. | |
| Analizada | Alta (8.4) | 0.23% | — | TD Advanced Dashboard | 21/2/2024 | 17/6/2026 | The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be used in production). This makes it easier for a compromised process to access banking information. | |
| Modificada | Media (5.3) | 0.91% | 💥 Exploit | Presstigers Simple JOB Board | 21/2/2024 | 17/6/2026 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all versions up to, and including, 2.10.8. This makes it possible for unauthenticated attackers to fetch arbitrary posts, which can be password… | |
| Analizada | Alta (7.5) | 74% | 💥 PoC | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Modificada | Media (6.1) | 0.35% | — | Automattic Crowdsignal Dashboard | 10/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Stimulsoft Dashboards.php | 6/2/2024 | 9/7/2026 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. | |
| Modificada | Media (6.1) | 0.83% | 💥 PoC | Stimulsoft Dashboard.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component. | |
| Modificada | Media (5.4) | 0.76% | 💥 PoC | Stimulsoft Dashboards.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |
| Modificada | Media (4.8) | 0.32% | — | Mangboard Mang Board | 31/1/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Board WP allows Stored XSS.This issue affects Mang Board WP: from n/a through 1.7.7. | |
| Modificada | Alta (8.8) | 0.19% | — | Custom Dashboard Widgets Project Custom Dashboard Widgets | 31/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1. | |
| Modificada | Alta (8.2) | 0.46% | — | Flatlogic React Dashboard | 30/1/2024 | 17/6/2026 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. |