Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.51%—Kanboard5/6/202317/6/2026
Kanboard is open source project management software that focuses on the Kanban methodology. A stored Cross site scripting (XSS) allows an attacker to execute arbitrary Javascript and any user who views the task containing the malicious code will be exposed to the XSS attack. Note: The default CSP header configuration…
ModificadaMedia (5.4)0.38%—Kanboard5/6/202317/6/2026
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to a missing access control vulnerability that allows a user with low privileges to create or transfer tasks to any project within the software, even if they have not been invited or the…
ModificadaMedia (6.5)0.63%—Kanboard5/6/202317/6/2026
Kanboard is open source project management software that focuses on the Kanban methodology. Versions prior to 1.2.30 are subject to an Insecure direct object reference (IDOR) vulnerability present in the application's URL parameter. This vulnerability enables any user to read files uploaded by any other user,…
ModificadaMedia (5.4)0.51%—Kanboard30/5/202317/6/2026
Kanboard is project management software that focuses on the Kanban methodology. Due to improper handling of elements under the `contentEditable` element, maliciously crafted clipboard content can inject arbitrary HTML tags into the DOM. A low-privileged attacker with permission to attach a document on a vulnerable…
ModificadaMedia (4.3)0.64%—Jenkins Kanboard6/2/201917/6/2026
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.
ModificadaMedia (6.1)1.3%—Kanboard4/2/201917/6/2026
app/Core/Paginator.php in Kanboard before 1.2.8 has XSS in pagination sorting.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.
ModificadaMedia (4.3)1.1%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.
ModificadaMedia (4.3)0.89%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user.
ModificadaMedia (4.3)1.1%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user.
ModificadaMedia (4.3)0.97%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description.
ModificadaMedia (4.3)1.4%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit a category of a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user.
ModificadaMedia (4.3)1.2%—Kanboard11/10/201717/6/2026
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.
ModificadaAlta (8.8)1.3%—Kanboard14/8/201717/6/2026
An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.
Orbitaley — Vulnerabilidades