Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.46% | — | Flatlogic React Dashboard | 30/1/2024 | 17/6/2026 | react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set. | |
| Modificada | Crítica (9.8) | 1.2% | — | Commscope Arris Surfboard Sbg6950ac2 Firmware | 26/1/2024 | 17/6/2026 | An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root. | |
| Modificada | Media (4.8) | 0.40% | — | Kanboard | 24/1/2024 | 17/6/2026 | Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature. | |
| Modificada | Baja (2.4) | 1.2% | 💥 PoC | Apple Magic Keyboard Firmware | 12/1/2024 | 17/6/2026 | A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to the accessory may be able to extract its Bluetooth pairing key and monitor Bluetooth traffic. | |
| Modificada | Alta (8.8) | 0.91% | — | Aarboard Jave2 | 12/1/2024 | 17/6/2026 | An issue was discovered in Jave2 version 3.3.1, allows attackers to execute arbitrary code via the FFmpeg function. | |
| Modificada | Alta (8.8) | 0.22% | — | Presstigers Simple JOB Board | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6. | |
| Modificada | Alta (8.8) | 1.2% | — | Kashipara Online Notice Board System | 4/1/2024 | 17/6/2026 | Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Online Notice Board System | 4/1/2024 | 17/6/2026 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Online Notice Board System | 4/1/2024 | 17/6/2026 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Crítica (9.8) | 0.67% | — | Kashipara Online Notice Board System | 4/1/2024 | 17/6/2026 | Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database. | |
| Modificada | Alta (7.2) | 0.82% | — | Kanbanwp Kanban Boards FOR Wordpress | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Modificada | Media (5.5) | 0.17% | — | Hihonor Honorboardapp | 29/12/2023 | 17/6/2026 | Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak. | |
| Modificada | Media (4.8) | 0.40% | — | Davidvongries Ultimate Dashboard | 21/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11. | |
| Modificada | Media (4.9) | 0.55% | — | Mainwp Dashboard | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MainWP MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance.This issue affects MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance: from n/a through 4.4.3.3. | |
| Modificada | Media (4.8) | 0.39% | — | Plugin-planet Dashboard Widget Suite | 14/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1. | |
| Modificada | Media (6.1) | 0.40% | — | Deconf Clicky Analytics Dashboard | 14/12/2023 | 17/6/2026 | A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla. | |
| Modificada | Crítica (9.8) | 0.71% | — | Joomcode Jcdashboard | 14/12/2023 | 17/6/2026 | Unauthenticated LFI/SSRF in JCDashboards component for Joomla. | |
| Modificada | Media (4.3) | 0.35% | — | Jenkins Deployment Dashboard | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs. | |
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.43% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (5.3) | 0.17% | — | Samsung Keyboard | 5/12/2023 | 17/6/2026 | Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack. | |
| Modificada | Media (4.8) | 0.38% | — | Davidvongries Ultimate Dashboard | 22/11/2023 | 17/6/2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… |