Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.27% | — | Mahmudul Hasan Arif Fluent BoardsAI | 15/4/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.2. | |
| Aplazada | Media (5.4) | 0.30% | — | Fluent BoardsAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.1. | |
| Aplazada | Alta (7) | 0.23% | — | Asus MotherboardsAIIntel B460 ChipsetAIIntel B560 ChipsetAIIntel B660 ChipsetAI+10 | 17/12/2025 | 30/9/2026 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Fluent BoardsAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injection.This issue affects FluentBoards: from n/a through <= 1.47. | |
| Aplazada | Media (5.5) | 0.17% | — | Samsung ClipboardserviceAI | 8/4/2025 | 17/6/2026 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability. | |
| Aplazada | Media (6.4) | 0.60% | 💥 PoC | Opensearch Dashboards-reportingAIOpensearchAI | 12/2/2025 | 17/6/2026 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 24/1/2025 | 17/6/2026 | IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion. | |
| Aplazada | Media (5.3) | 0.42% | — | Kanbanwp Kanban Boards FOR WordpressAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Aplazada | Media (6.1) | 0.26% | — | Opensearch DashboardsAIOpensearch SecurityAI | 23/8/2024 | 17/6/2026 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and… | |
| Aplazada | Alta (7.1) | 0.35% | — | Kanbanwp Kanban BoardsAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kanban for WordPress Kanban Boards for WordPress allows Reflected XSS.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 PoC | Stimulsoft Dashboards.php | 6/2/2024 | 9/7/2026 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. | |
| Modificada | Media (5.4) | 0.76% | 💥 PoC | Stimulsoft Dashboards.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |
| Modificada | Alta (7.2) | 0.82% | — | Kanbanwp Kanban Boards FOR Wordpress | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21. | |
| Modificada | Media (6.5) | 0.52% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. | |
| Modificada | Media (6.4) | 0.11% | — | Intel NUC Performance KIT AND Mini PC Nuc10i3fnh FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhf FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhfa FirmwareIntel NUC Performance KIT AND Mini PC Nuc10i3fnhja Firmware+170 | 11/8/2023 | 17/6/2026 | Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.17% | — | Intel NUC 13 Extreme Compute Element Nuc13sbbi5 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi5f FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7 FirmwareIntel NUC 13 Extreme Compute Element Nuc13sbbi7f Firmware+151 | 11/8/2023 | 17/6/2026 | Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 7 Enthusiast Nuc7i7bnkq FirmwareIntel NUC 7 Enthusiast Nuc7i7bnhxg FirmwareIntel NUC KIT Nuc7i7dnhe FirmwareIntel NUC KIT Nuc7i7dnke Firmware+207 | 11/8/2023 | 17/6/2026 | Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel NUC 11 Performance KIT Nuc11pahi3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11paki3 FirmwareIntel NUC 11 Performance KIT Nuc11pahi5 Firmware+84 | 11/8/2023 | 17/6/2026 | Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.8) | 0.55% | — | Kanbanwp Kanban Boards FOR Wordpress | 27/6/2023 | 17/6/2026 | The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (4.8) | 0.37% | — | Kanbanwp Kanban Boards | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Kanbanwp Kanban Boards FOR Wordpress | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kanban for WordPress Kanban Boards for WordPress plugin <= 2.5.20 versions. | |
| Modificada | Media (4.3) | 0.67% | — | Mattermost Boards | 18/1/2022 | 17/6/2026 | Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, which allows authenticated and unauthorized users to access this information resulting in sensitive & private information disclosure. | |
| Modificada | Alta (7.5) | 0.72% | — | Mattermost Boards | 18/1/2022 | 17/6/2026 | Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of Boards, which allows an attacker to reuse old session token for authorization. |