Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Redash | 11/6/2020 | 17/6/2026 | Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is potent and provides a lot of flexibility in terms of being able to craft HTTP requests e.g., by adding headers, selecting… | |
| Modificada | Crítica (9.8) | 1.8% | — | Learndash | 1/4/2020 | 17/6/2026 | LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection. | |
| Modificada | Alta (7.5) | 2.2% | — | HP Oneview Global Dashboard | 4/3/2020 | 17/6/2026 | HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | |
| Modificada | Media (5.4) | 3.5% | 💥 Exploit | Learndash | 16/1/2020 | 17/6/2026 | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | |
| Modificada | Media (4.3) | 0.41% | — | Dash CoreOfficialdapscoin Decentralized Anonymous Payment SystemPivx Private Instant Verified Transactions | 4/12/2019 | 17/6/2026 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wallets to send HTTP requests to arbitrary locations, both on the local network and on the internet. This is a serious threat to user privacy, since it can possibly leak their IP address and the fact… | |
| Modificada | Crítica (9.8) | 1.3% | — | Doordash | 15/10/2019 | 17/6/2026 | In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat. | |
| Modificada | Media (6.1) | 0.94% | — | Realbigplugins Client Dash | 10/10/2019 | 17/6/2026 | The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS. | |
| Modificada | Media (5.4) | 0.57% | — | Nodered Node-red-dashboard | 8/10/2019 | 17/6/2026 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. | |
| Modificada | Media (6.1) | 0.92% | — | Wpfactory Download Plugins AND Themes From Dashboard | 7/10/2019 | 17/6/2026 | includes/settings/class-alg-download-plugins-settings.php in the download-plugins-dashboard plugin through 1.5.0 for WordPress has multiple unauthenticated stored XSS issues. | |
| Modificada | Media (5.9) | 1.5% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an attacker to substitute downloaded resources… | |
| Modificada | Alta (7.5) | 0.66% | — | Sandisk SSD DashboardWesterndigital SSD Dashboard | 30/9/2019 | 17/6/2026 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available. | |
| Modificada | Crítica (9.8) | 2.1% | — | Dash10 Oauth Server | 26/9/2019 | 17/6/2026 | The oauth2-provider plugin before 3.1.5 for WordPress has incorrect generation of random numbers. | |
| Modificada | Alta (7.2) | 1.7% | — | Trivetechnology Wp-stats-dashboard | 20/9/2019 | 17/6/2026 | The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Dashboard View | 12/9/2019 | 17/6/2026 | Jenkins Dashboard View Plugin 2.11 and earlier did not escape build descriptions, resulting in a cross-site scripting vulnerability exploitable by users able to change build descriptions. | |
| Modificada | Alta (8.8) | 0.67% | — | Erident Custom Login AND Dashboard Project Erident Custom Login AND Dashboard | 16/8/2019 | 17/6/2026 | The erident-custom-login-and-dashboard plugin before 3.5 for WordPress has CSRF. | |
| Modificada | Crítica (9.1) | 5.0% | 💥 PoC | LodashNetapp Active IQ Unified ManagerNetapp Service Level ManagerRedhat Virtualization Manager+17 | 26/7/2019 | 17/6/2026 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | |
| Modificada | Media (6.5) | 3.2% | — | Lodash | 17/7/2019 | 17/6/2026 | lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11. | |
| Modificada | Alta (7.5) | 1.5% | — | Ddrt Dashcom Live Firmware | 9/7/2019 | 17/6/2026 | Lack of authentication in file-viewing components in DDRT Dashcom Live 2019-05-09 allows anyone to remotely access all claim details by visiting easily guessable dashboard/uploads/claim_files/claim_id_ URLs. | |
| Modificada | Alta (7.5) | 1.5% | — | Ddrt Dashcom Live Firmware | 9/7/2019 | 17/6/2026 | Lack of authentication in case-exporting components in DDRT Dashcom Live through 2019-05-08 allows anyone to remotely access all claim details by visiting easily guessable exportpdf/all_claim_detail.php?claim_id= URLs. | |
| Modificada | Crítica (9.8) | 1.5% | — | Glpi Dashboard Project Glpi Dashboard | 2/6/2019 | 17/6/2026 | Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh. | |
| Modificada | Media (5.8) | 1.6% | — | Wso2 Dashboard Server | 14/5/2019 | 17/6/2026 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to force the application to perform requests to the internal workstation (port-scanning) and to perform requests to adjacent workstations (network-scanning), aka SSRF. | |
| Modificada | Media (4.8) | 1.0% | — | Wso2 Dashboard Server | 14/5/2019 | 17/6/2026 | An issue was discovered in WSO2 Dashboard Server 2.0.0. It is possible to inject a JavaScript payload that will be stored in the database and then displayed and executed on the same page, aka XSS. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the HTTP request-parsing function of the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an unlimited and arbitrary write to memory, resulting in code execution. | |
| Modificada | Alta (7.5) | 1.4% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. The HTTP server could allow an attacker to overwrite the root directory of the server, resulting in a denial of service. An attacker can send an HTTP POST request to trigger… |