Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.59%—Wartsila Fos-onboardAI15/9/202624/9/2026
A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.
AplazadaCrítica (9.5)0.51%—Wartsila Fos-onboardAI15/9/202624/9/2026
A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.
AplazadaAlta (7.1)0.30%—LaradashboardAI14/9/202623/9/2026
laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store,…
AplazadaAlta (8.6)0.82%—LaradashboardAI14/9/202623/9/2026
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation,…
AplazadaMedia (5.1)0.24%—LaradashboardAI14/9/202623/9/2026
LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application…
AplazadaAlta (7.1)0.47%—Lara DashboardAI9/9/20269/9/2026
Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by…
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
AplazadaMedia (6.3)0.37%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
AplazadaAlta (8.3)0.11%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
AplazadaAlta (8.3)0.15%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
AplazadaAlta (8.6)1.1%—Laradashboard Lara DashboardAI7/9/202610/9/2026
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
AplazadaAlta (8.6)0.71%—Laradashboard Lara DashboardAI7/9/20268/9/2026
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified…
AplazadaMedia (5.3)0.53%—Lara DashboardAI7/9/20269/9/2026
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits…
Pendiente de análisisMedia (6.5)0.35%—Redhat Openshift AIAIRedhat Odh-dashboardAI7/9/20268/9/2026
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the…
AplazadaAlta (8.8)0.25%—Nokri JOB BoardAI5/9/20268/9/2026
The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaCrítica (9.3)1.1%—Laradashboard Lara DashboardAI5/9/202618/9/2026
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to…
AplazadaAlta (8.8)0.20%—Mangboard Mang Board WPAI2/9/20262/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.
AplazadaCrítica (9.8)0.43%💥 PoCWpmudev Wpmu DEV DashboardAI28/8/202628/8/2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated…
AplazadaAlta (7.2)0.54%—Fluent Boards PROAI27/8/202628/8/2026
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
AplazadaMedia (6.8)0.50%—Fluent Boards PROAI27/8/202628/8/2026
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
AplazadaCrítica (9.1)0.50%—Fluent Boards PROAI27/8/202628/8/2026
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
AplazadaMedia (6.5)0.22%—Fluent Boards PROAI27/8/202628/8/2026
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
Pendiente de análisisAlta (7.5)0.13%—Vanderbilt Industries Acre Security Spc5300AIVanderbilt Industries Main BoardAI26/8/20269/9/2026
An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.
AplazadaMedia (6.5)0.22%—Thingsboard Professional EditionAI26/8/20269/9/2026
A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation…
AplazadaAlta (8.8)0.86%—Mangboard Mang Board WPAI26/8/202626/8/2026
The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a…