Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.7% | — | Apache Apisix Dashboard | 8/6/2021 | 17/6/2026 | In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate users to configure external network access. In the IP allowed list restriction, a risky function was used for the IP acquisition, which made it possible to bypass the network limit. At the same time,… | |
| Modificada | Media (5.4) | 73% | — | Jenkins Dashboard View | 11/5/2021 | 17/6/2026 | Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission. | |
| Modificada | Media (5.3) | 2.1% | 💥 Exploit | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+16 | 12/4/2021 | 17/6/2026 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline Optimizer WordPress plugin before 1.3.7.3, Thrive Leads WordPress plugin before 2.3.9.4, Thrive Ultimatum WordPress plugin before 2.3.9.4, Thrive Quiz Builder WordPress plugin before 2.3.9.4, Thrive… | |
| Modificada | Media (4.3) | 0.81% | — | Glpi-project Dashboard | 6/4/2021 | 17/6/2026 | The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used. | |
| Modificada | Media (5.3) | 0.93% | — | Redash | 18/3/2021 | 17/6/2026 | Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization. | |
| Modificada | Alta (8.1) | 1.1% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase EspressReports ES 7 Update 9. An authenticated user is able to navigate to the MenuPage section of the application, and change the frmsrc parameter value to retrieve and execute external files or payloads. | |
| Modificada | Media (4.3) | 0.45% | — | Quadbase Espressdashboard | 15/3/2021 | 17/6/2026 | An issue was discovered in Quadbase ExpressDashboard (EDAB) 7 Update 9. It allows CSRF. An attacker may be able to trick an authenticated user into changing the email address associated with their account. | |
| Modificada | Crítica (9.8) | 46% | — | Docker Dashboard Project Docker Dashboard | 2/3/2021 | 17/6/2026 | rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product. | |
| Modificada | Alta (7.2) | 21% | 💥 Exploit | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+19 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | |
| Modificada | Media (5.3) | 7.3% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+15 | 15/2/2021 | 17/6/2026 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Nodered Node-red-dashboard | 26/1/2021 | 17/6/2026 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | |
| Modificada | Media (6.1) | 0.78% | — | Uncannyowl TIN Canny Reporting FOR Learndash | 23/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Owl Tin Canny LearnDash Reporting before 3.4.4 allows authenticated remote attackers to inject arbitrary web script or HTML via the search_key GET Parameter in TinCan_Content_List_Table.php, message GET Parameter in licensing.php, tc_filter_group parameter… | |
| Modificada | Media (6.1) | 0.78% | — | Uncannyowl Uncanny Groups FOR Learndash | 23/12/2020 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Uncanny Groups for LearnDash before v3.7 allow authenticated remote attackers to inject arbitrary JavaScript or HTML via the ulgm_code_redeem POST Parameter in user-code-redemption.php, the ulgm_user_first POST Parameter in user-registration-form.php, the… | |
| Modificada | Alta (7.8) | 0.43% | — | Westerndigital Dashboard | 12/12/2020 | 17/6/2026 | Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account. | |
| Modificada | Alta (8.7) | 1.3% | — | Cogboard Red-dashboard | 9/12/2020 | 17/6/2026 | Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code. By… | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level. | |
| Modificada | Media (5.4) | 0.63% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an… | |
| Modificada | Alta (7.2) | 2.1% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage. | |
| Modificada | Crítica (9.9) | 3.3% | — | Openstack Blazar-dashboard | 16/10/2020 | 17/6/2026 | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host… | |
| Modificada | Media (6.1) | 1.0% | — | Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory | 31/8/2020 | 17/6/2026 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. | |
| Modificada | Media (6.5) | 0.73% | — | Prestashop Dashboard Products | 21/7/2020 | 17/6/2026 | In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0. | |
| Modificada | Alta (7.4) | 5.2% | — | LodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+14 | 15/7/2020 | 17/6/2026 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | |
| Modificada | Media (6.1) | 0.78% | — | Digdash | 15/6/2020 | 17/6/2026 | An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the login menu. | |
| Modificada | Alta (7.8) | 0.91% | — | Digdash | 15/6/2020 | 17/6/2026 | An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java application. By providing an attacker-controlled URL, the client will obtain a rogue… | |
| Modificada | Alta (7.5) | 1.0% | — | Digdash | 15/6/2020 | 17/6/2026 | An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application credentials. For a request to an internal… |