Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.59% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard. | |
| Aplazada | Crítica (9.5) | 0.51% | — | Wartsila Fos-onboardAI | 15/9/2026 | 24/9/2026 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard. | |
| Aplazada | Alta (7.1) | 0.30% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store,… | |
| Aplazada | Alta (8.6) | 0.82% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation,… | |
| Aplazada | Media (5.1) | 0.24% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application… | |
| Aplazada | Alta (7.1) | 0.47% | — | Lara DashboardAI | 9/9/2026 | 9/9/2026 | Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by… | |
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Aplazada | Media (6.3) | 0.37% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link. | |
| Aplazada | Alta (8.3) | 0.11% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user. | |
| Aplazada | Alta (8.3) | 0.15% | — | PimboardsAI | 8/9/2026 | 11/9/2026 | The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information. | |
| Aplazada | Alta (8.6) | 1.1% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 10/9/2026 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |
| Aplazada | Alta (8.6) | 0.71% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 8/9/2026 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified… | |
| Aplazada | Media (5.3) | 0.53% | — | Lara DashboardAI | 7/9/2026 | 9/9/2026 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… | |
| Aplazada | Alta (8.8) | 0.25% | — | Nokri JOB BoardAI | 5/9/2026 | 8/9/2026 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Laradashboard Lara DashboardAI | 5/9/2026 | 18/9/2026 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to… | |
| Aplazada | Alta (8.8) | 0.20% | — | Mangboard Mang Board WPAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions. | |
| Aplazada | Crítica (9.8) | 0.43% | 💥 PoC | Wpmudev Wpmu DEV DashboardAI | 28/8/2026 | 28/8/2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated… | |
| Aplazada | Alta (7.2) | 0.54% | — | Fluent Boards PROAI | 27/8/2026 | 28/8/2026 | Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions. | |
| Aplazada | Media (6.8) | 0.50% | — | Fluent Boards PROAI | 27/8/2026 | 28/8/2026 | Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Fluent Boards PROAI | 27/8/2026 | 28/8/2026 | Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Fluent Boards PROAI | 27/8/2026 | 28/8/2026 | Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | Vanderbilt Industries Acre Security Spc5300AIVanderbilt Industries Main BoardAI | 26/8/2026 | 9/9/2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers. | |
| Aplazada | Media (6.5) | 0.22% | — | Thingsboard Professional EditionAI | 26/8/2026 | 9/9/2026 | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms comments functionality. An authenticated customer user can manipulate the respective API request parameters to create or modify system-generated alarm comments. This allows unauthorized impersonation… | |
| Aplazada | Alta (8.8) | 0.86% | — | Mangboard Mang Board WPAI | 26/8/2026 | 26/8/2026 | The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This is due to flawed HMAC generation in the mbw_get_hash_key() function that uses the current user's identity instead of the cookie username parameter when a… |