Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
507 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.8) | 0.16% | — | Chengdu Qilu Technology LudashiAI | 13/9/2026 | 15/9/2026 | A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published… | |
| Aplazada | Alta (7.1) | 0.47% | — | Lara DashboardAI | 9/9/2026 | 9/9/2026 | Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by… | |
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Aplazada | Alta (8.6) | 1.1% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 10/9/2026 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |
| Aplazada | Alta (8.6) | 0.71% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 8/9/2026 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified… | |
| Aplazada | Media (5.3) | 0.53% | — | Lara DashboardAI | 7/9/2026 | 9/9/2026 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… | |
| Aplazada | Crítica (9.8) | 0.30% | — | MemberdashAI | 6/9/2026 | 8/9/2026 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including… | |
| Aplazada | Media (5.4) | 0.16% | — | Learndash LMSAI | 5/9/2026 | 8/9/2026 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Laradashboard Lara DashboardAI | 5/9/2026 | 18/9/2026 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to… | |
| Aplazada | Alta (7.5) | 0.38% | — | LearndashAI | 4/9/2026 | 8/9/2026 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the first file. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Wpmudev Wpmu DEV DashboardAI | 28/8/2026 | 28/8/2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated… | |
| Aplazada | Baja (2.3) | 0.18% | — | MCP Server DashAI | 27/8/2026 | 24/9/2026 | The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its network mode with the interface restricted to loopback and no transport-security settings, so a name that had been pointed at the loopback address still… | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Opensearch DashboardsAI | 20/8/2026 | 25/8/2026 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code… | |
| Aplazada | Media (5.3) | 0.32% | — | LightdashAI | 20/8/2026 | 24/9/2026 | Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In affected versions both call fetch on the stored URL directly. The… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | Opensearch DashboardsAI | 18/8/2026 | 20/8/2026 | Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mapsteps UG Ultimate Dashboard PROAI | 18/8/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2. | |
| Aplazada | Media (6.4) | 0.33% | — | SuredashAI | 16/8/2026 | 20/8/2026 | The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute in all versions up to, and including, 1.10.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.25% | — | SuredashAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.60% | — | Opendatahub ODH DashboardAI | 10/8/2026 | 14/8/2026 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Redhat ODH DashboardAI | 10/8/2026 | 28/9/2026 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to… | |
| Aplazada | Crítica (9.8) | 0.73% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | |
| Aplazada | Crítica (9.8) | 10% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. |