Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

507 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (1.8)0.16%—Chengdu Qilu Technology LudashiAI13/9/202615/9/2026
A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published…
AplazadaAlta (7.1)0.47%—Lara DashboardAI9/9/20269/9/2026
Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by…
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
AplazadaAlta (8.6)1.1%—Laradashboard Lara DashboardAI7/9/202610/9/2026
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
AplazadaAlta (8.6)0.71%—Laradashboard Lara DashboardAI7/9/20268/9/2026
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified…
AplazadaMedia (5.3)0.53%—Lara DashboardAI7/9/20269/9/2026
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits…
Pendiente de análisisMedia (6.5)0.35%—Redhat Openshift AIAIRedhat Odh-dashboardAI7/9/20268/9/2026
A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the…
AplazadaCrítica (9.8)0.30%—MemberdashAI6/9/20268/9/2026
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including…
AplazadaMedia (5.4)0.16%—Learndash LMSAI5/9/20268/9/2026
The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment…
AplazadaCrítica (9.3)1.1%—Laradashboard Lara DashboardAI5/9/202618/9/2026
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to…
AplazadaAlta (7.5)0.38%—LearndashAI4/9/20268/9/2026
The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for…
AplazadaCrítica (9.8)0.43%—Wpmudev Wpmu DEV DashboardAI28/8/202628/8/2026
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated…
AplazadaBaja (2.3)0.18%—MCP Server DashAI27/8/202624/9/2026
The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still…
Pendiente de análisisMedia (6.2)0.52%—Opensearch Dashboards-observabilityAI21/8/202627/8/2026
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web…
Pendiente de análisisAlta (8.7)0.66%—Opensearch DashboardsAI20/8/202625/8/2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code…
AplazadaMedia (5.3)0.32%—LightdashAI20/8/202624/9/2026
Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL directly. The…
Pendiente de análisisAlta (8.7)0.72%—Opensearch DashboardsAI18/8/202620/8/2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
AplazadaAlta (7.1)0.25%—Mapsteps UG Ultimate Dashboard PROAI18/8/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.
AplazadaMedia (6.4)0.33%—SuredashAI16/8/202620/8/2026
The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaAlta (7.1)0.25%—SuredashAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
Pendiente de análisisAlta (8.8)0.60%—Opendatahub ODH DashboardAI10/8/202614/8/2026
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like…
Pendiente de análisisAlta (8.8)0.52%—Redhat ODH DashboardAI10/8/202628/9/2026
A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to…
AplazadaCrítica (9.8)0.73%—WgdashboardAI6/8/20263/9/2026
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.
AplazadaCrítica (9.8)10%—WgdashboardAI6/8/20263/9/2026
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.
AplazadaCrítica (9.8)0.56%—WgdashboardAI6/8/20263/9/2026
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.