Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
1618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.37% | — | Plugin-planet Dashboard Widget Suite | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions. | |
| Modificada | Media (6.1) | 0.53% | — | Bestwebsoft JOB Board | 2/5/2023 | 17/6/2026 | A vulnerability classified as problematic was found in BestWebSoft Job Board Plugin 1.0.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp HCI Baseboard Management Controller | 1/5/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring subsystem can be exploited to achieve local privilege escalation. Both io_install_fixed_file and its callers call fput in a file in case of an error, causing a reference underflow which leads to a use-after-free vulnerability. We recommend upgrading past… | |
| Modificada | Media (5.3) | 0.64% | — | Infopop Ultimate Bulletin Board | 27/4/2023 | 17/6/2026 | Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be disclosed by unauthenticated users via the quote reply feature. | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Alta (7.2) | 1.3% | — | Pwsdashboard Personal Weather Station Dashboard | 25/4/2023 | 17/6/2026 | PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a… | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp HCI Baseboard Management Controller | 24/4/2023 | 17/6/2026 | A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and execute arbitrary code in the context of the kernel. | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Crítica (9.8) | 1.5% | — | Timmystudios Fast Typing Keyboard | 14/4/2023 | 17/6/2026 | Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution. | |
| Modificada | Media (4.8) | 0.37% | — | Announce From THE Dashboard Project Announce From THE Dashboard | 7/4/2023 | 17/6/2026 | Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions. | |
| Modificada | Media (5.3) | 0.44% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data… | |
| Modificada | Media (6.5) | 0.24% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could allow the renaming of files in the IGSS project report directory, this could lead to denial of service when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data… | |
| Modificada | Media (5.3) | 0.24% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause access to delete files in the IGSS project report directory, this could lead to loss of data when an attacker sends specific crafted messages to the Data Server TCP port. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.61% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in Custom Reports that could cause a macro to be executed, potentially leading to remote code execution when a user opens a malicious report file planted by an attacker. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (8.8) | 0.73% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Custom Reports that could cause a remote code execution when a victim tries to open a malicious report. Affected Products: IGSS Data Server(IGSSdataServer.exe)(V16.0.0.23040 and prior), IGSS… | |
| Modificada | Alta (7.8) | 6.5% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.40% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server that could cause manipulation of dashboard files in the IGSS project report directory, when an attacker sends specific crafted messages to the Data Server TCP port, this could lead to remote code execution when a victim… | |
| Modificada | Alta (8.8) | 0.88% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow the creation of a malicious report file in the IGSS project report directory, this could lead to remote code execution when a victim eventually opens the report. Affected Products: IGSS Data… | |
| Modificada | Alta (8.8) | 0.86% | — | Thingsboard | 1/3/2023 | 9/7/2026 | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileges (vertically) and become an Administrator (TENANT_ADMIN) or (SYS_ADMIN) on the web application. It is important to note that in order to accomplish this, the attacker must know the corresponding… | |
| Modificada | Media (6.1) | 0.52% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient user input validation. An… | |
| Modificada | Alta (7.5) | 0.95% | — | Cisco Nexus Dashboard | 1/3/2023 | 17/6/2026 | A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could exploit this vulnerability by sending a continuous stream of… | |
| Modificada | Alta (7.1) | 0.61% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 26/2/2023 | 17/6/2026 | In the Linux kernel 6.0.8, there is an out-of-bounds read in ntfs_attr_find in fs/ntfs/attrib.c. | |
| Modificada | Media (6.1) | 0.40% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2). | |
| Modificada | Media (6.1) | 0.37% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.) | |
| Modificada | Media (5.4) | 0.39% | — | Squaredup Dashboard Server | 23/2/2023 | 17/6/2026 | SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2). |