Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Kanboard | 5/6/2023 | 17/6/2026 | Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be exposed to the XSS attack. Note: The default CSP header configuration… | |
| Modificada | Media (5.4) | 0.38% | — | Kanboard | 5/6/2023 | 17/6/2026 | Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access control vulnerability that allows a user with low privileges to create or transfer tasks to any project within the software, even if they have not been invited or the… | |
| Modificada | Media (6.5) | 0.63% | — | Kanboard | 5/6/2023 | 17/6/2026 | Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direct object reference (IDOR) vulnerability present in the application's URL parameter. This vulnerability enables any user to read files uploaded by any other user,… | |
| Modificada | Media (5.4) | 0.51% | — | Kanboard | 30/5/2023 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable… | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Kanboard | 6/2/2019 | 17/6/2026 | A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL. | |
| Modificada | Media (6.1) | 1.3% | — | Kanboard | 4/2/2019 | 17/6/2026 | app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user. | |
| Modificada | Media (4.3) | 1.1% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user. | |
| Modificada | Media (4.3) | 0.89% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user. | |
| Modificada | Media (4.3) | 1.1% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user. | |
| Modificada | Media (4.3) | 0.97% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description. | |
| Modificada | Media (4.3) | 1.4% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user. | |
| Modificada | Media (4.3) | 1.2% | — | Kanboard | 11/10/2017 | 17/6/2026 | In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user. | |
| Modificada | Alta (8.8) | 1.3% | — | Kanboard | 14/8/2017 | 17/6/2026 | An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46. |