Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.7% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several stack-based buffer overflow vulnerabilities have been identified, which may allow an… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several untrusted pointer dereference vulnerabilities have been identified, which may allow an… | |
| Modificada | Alta (7.5) | 2.2% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an external control of file name or path vulnerability has been identified, which may allow an… | |
| Modificada | Media (6.1) | 0.63% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an origin validation error vulnerability has been identified, which may allow an attacker can… | |
| Modificada | Alta (7.5) | 1.7% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an information exposure vulnerability through directory listing has been identified, which may… | |
| Modificada | Crítica (9.8) | 4.0% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to execute… | |
| Modificada | Alta (8.1) | 0.74% | 💥 PoC | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials. | |
| Modificada | Alta (7.5) | 1.5% | — | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts. | |
| Modificada | Alta (7.5) | 1.5% | — | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports. | |
| Modificada | Alta (7.8) | 0.27% | — | Cisecurity Cis-cat PRO Dashboard | 31/1/2018 | 17/6/2026 | In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administrative user's e-mail address and send a forgot password email to themselves, thereby gaining administrative access. | |
| Modificada | Alta (7.8) | 1.1% | — | Linux-dash Project Linux-dash | 3/1/2018 | 17/6/2026 | Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are parsed and then executed resulting in code execution on the server, potentially as root. | |
| Modificada | Media (6.1) | 0.64% | — | Wso2 Application ServerWso2 Business Process ServerWso2 Business Rules ServerWso2 Complex Event Processor+4 | 4/10/2017 | 17/6/2026 | The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS. | |
| Modificada | Media (4.8) | 3.8% | 💥 Exploit | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | User Dashboard Project User Dashboard | 11/9/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.3) | 0.67% | 💥 Exploit | Dashlane | 4/8/2017 | 17/6/2026 | Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory. | |
| Modificada | Alta (8.8) | 0.45% | — | IBM Dashboard Application Services HUB | 24/2/2017 | 17/6/2026 | IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1998714. | |
| Modificada | Crítica (9.8) | 2.4% | — | IBM Dashdb Local | 8/2/2017 | 17/6/2026 | IBM dashDB Local uses hard-coded credentials that could allow a remote attacker to gain access to the Docker container or database. | |
| Modificada | Media (5.9) | 0.75% | — | IBM Dashboard Application Services HUB | 2/2/2017 | 17/6/2026 | IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL certificate. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. | |
| Modificada | Crítica (9.8) | 3.2% | — | Openstack Mitaka-muranoOpenstack MuranoOpenstack Murano-dashboardOpenstack Python-muranoclient | 26/9/2016 | 17/6/2026 | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows… | |
| Modificada | Crítica (9.8) | 3.7% | 💥 PoC | Redhat DashbuilderRedhat Jboss BPM SuiteRedhat Jboss Enterprise Brms Platform | 5/8/2016 | 17/6/2026 | SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI. | |
| Modificada | Media (6.8) | 1.0% | — | Twitterdash Project Twitterdash | 19/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the username_twitterDash parameter in the twitterDash.php page to… | |
| Modificada | Media (5.4) | 0.27% | — | Dakshaa Neeku Naaku Dash Dash | 15/10/2014 | 17/6/2026 | The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Mini Mail Dashboard Widget Project Mini Mail Dashboard Widget | 17/9/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email. | |
| Modificada | Media (4.3) | 0.94% | — | Puppet DashboardPuppet Enterprise | 14/3/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields. | |
| Modificada | Media (5.8) | 1.2% | — | IBM Websphere Dashboard Framework | 14/2/2014 | 17/6/2026 | The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary directory. |