Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.41% | — | Nautobot-plugin-device-onboarding | 21/11/2023 | 17/6/2026 | The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to onboarding task are visible via Job Results… | |
| Modificada | Media (4.4) | 0.21% | — | Intel NUC 11 PRO KIT Nuc11tnkv50z FirmwareIntel NUC 11 PRO KIT Nuc11tnhv70l FirmwareIntel NUC 11 PRO KIT Nuc11tnhv50l FirmwareIntel NUC 11 PRO Board Nuc11tnbv7 Firmware+52 | 14/11/2023 | 17/6/2026 | Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.7) | 0.24% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access | |
| Modificada | Media (6.7) | 0.23% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel Compute Module Hns2600bp FirmwareIntel Compute Module Hns2600bpb FirmwareIntel Compute Module Hns2600bpb24 FirmwareIntel Compute Module Hns2600bpb24r Firmware+32 | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.21% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh FirmwareIntel Server Board M20ntp2sb FirmwareIntel Server System M20ntp1ur304 Firmware+29 | 14/11/2023 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.21% | — | Intel Server Board M70klp2sb FirmwareIntel Server System M70klp4s2uhh Firmware | 14/11/2023 | 17/6/2026 | Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.31% | — | Presstigers Simple JOB Board | 10/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board plugin <= 2.10.3 versions. | |
| Modificada | Media (5.4) | 0.43% | — | Ziteboard | 7/11/2023 | 17/6/2026 | The Ziteboard Online Whiteboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ziteboard' shortcode in versions up to, and including, 2.9.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Modificada | Media (4.8) | 0.35% | — | Properfraction Admin BAR & Dashboard Access Control | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions. | |
| Modificada | Media (6.5) | 0.52% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. | |
| Modificada | Media (5.4) | 0.51% | — | Maheshwaghmare Copy Anything TO Clipboard | 20/10/2023 | 17/6/2026 | The Copy Anything to Clipboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'copy' shortcode in versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.1) | 0.33% | — | Extendwings Opcache Dashboard | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions. | |
| Modificada | Media (4.3) | 0.24% | — | Chiefonboarding | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository chiefonboarding/chiefonboarding prior to v2.0.47. | |
| Modificada | Alta (8.8) | 0.27% | — | Mangboard Mang Board | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hometory Mang Board WP plugin <= 1.7.6 versions. | |
| Modificada | Alta (8.8) | 0.59% | — | Wazuh-dashboardWazuh-kibana-app | 9/10/2023 | 17/6/2026 | Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their… | |
| Modificada | Alta (8.8) | 1.0% | — | Thingsboard | 6/10/2023 | 17/6/2026 | ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint). | |
| Modificada | Alta (7.5) | 0.47% | — | Opendatahub Open Data HUB DashboardRedhat Openshift Data Science | 4/10/2023 | 17/6/2026 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret. | |
| Modificada | Crítica (9.8) | 1.2% | — | Open-falcon Dashboard | 11/8/2023 | 17/6/2026 | An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface. | |
| Modificada | Alta (7.8) | 0.10% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.4) | 0.11% | — | Intel NUC Performance KIT AND Mini PC Nuc10i3fnh FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhf FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhfa FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhja Firmware+170 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC Rugged KIT Nuc8cchb FirmwareIntel NUC Rugged KIT Nuc8cchbn FirmwareIntel NUC Rugged KIT Nuc8cchkrn FirmwareIntel NUC Rugged KIT Nuc8cchkr Firmware+67 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Intel NUC KIT Nuc7i7bnhx1 FirmwareIntel NUC 7 Home Nuc7i5bnkp FirmwareIntel NUC 7 Home Nuc7i3bnhxf FirmwareIntel NUC 7 Enthusiast Nuc7i7bnkq Firmware+19 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. |