Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.3%—Redash11/6/202017/6/2026
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting…
ModificadaCrítica (9.8)1.8%—Learndash1/4/202017/6/2026
LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.
ModificadaAlta (7.5)2.2%—HP Oneview Global Dashboard4/3/202017/6/2026
HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.
ModificadaAlta (7.8)0.45%—Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe19/2/202017/6/2026
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
ModificadaMedia (5.4)3.5%💥 ExploitLearndash16/1/202017/6/2026
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
ModificadaMedia (4.3)0.41%—Dash CoreOfficialdapscoin Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions4/12/201917/6/2026
An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact…
ModificadaCrítica (9.8)1.3%—Doordash15/10/201917/6/2026
In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
ModificadaMedia (6.1)0.94%—Realbigplugins Client Dash10/10/201917/6/2026
The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
ModificadaMedia (5.4)0.57%—Nodered Node-red-dashboard8/10/201917/6/2026
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
ModificadaMedia (6.1)0.92%—Wpfactory Download Plugins AND Themes From Dashboard7/10/201917/6/2026
includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues.
ModificadaMedia (5.9)1.5%—Sandisk SSD DashboardWesterndigital SSD Dashboard30/9/201917/6/2026
Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources…
ModificadaAlta (7.5)0.66%—Sandisk SSD DashboardWesterndigital SSD Dashboard30/9/201917/6/2026
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available.
ModificadaCrítica (9.8)2.1%—Dash10 Oauth Server26/9/201917/6/2026
The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers.
ModificadaAlta (7.2)1.7%—Trivetechnology Wp-stats-dashboard20/9/201917/6/2026
The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection.
ModificadaMedia (5.4)0.73%—Jenkins Dashboard View12/9/201917/6/2026
Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions.
ModificadaAlta (8.8)0.67%—Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard16/8/201917/6/2026
The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF.
ModificadaCrítica (9.1)5.0%💥 PoCLodashNetapp Active IQ Unified ManagerNetapp Service Level ManagerRedhat Virtualization Manager+1726/7/201917/6/2026
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
ModificadaMedia (6.5)3.2%—Lodash17/7/201917/6/2026
lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.
ModificadaAlta (7.5)1.5%—Ddrt Dashcom Live Firmware9/7/201917/6/2026
Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs.
ModificadaAlta (7.5)1.5%—Ddrt Dashcom Live Firmware9/7/201917/6/2026
Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs.
ModificadaCrítica (9.8)1.5%—Glpi Dashboard Project Glpi Dashboard2/6/201917/6/2026
Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh.
ModificadaMedia (5.8)1.6%—Wso2 Dashboard Server14/5/201917/6/2026
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF.
ModificadaMedia (4.8)1.0%—Wso2 Dashboard Server14/5/201917/6/2026
An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS.
ModificadaCrítica (9.8)2.9%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code execution.
ModificadaAlta (7.5)1.4%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. The HTTP server could allow an attacker to overwrite the root directory of the server, resulting in a denial of service. An attacker can send an HTTP POST request to trigger…