Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.31% | — | Fluent Boards PROAI | 24/8/2026 | 24/8/2026 | Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions. | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Opensearch DashboardsAI | 20/8/2026 | 25/8/2026 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code… | |
| Aplazada | Media (6.5) | 0.44% | 💥 PoC | 4gaboardsAI | 18/8/2026 | 9/9/2026 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show actions rely only on the default… | |
| Aplazada | Alta (7.6) | 0.40% | — | 4gaboardsAI | 18/8/2026 | 9/9/2026 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in… | |
| Aplazada | Alta (8.8) | 0.47% | — | 4gaboardsAI | 18/8/2026 | 9/9/2026 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits… | |
| Aplazada | Alta (8.8) | 0.59% | — | 4gaboardsAI | 18/8/2026 | 9/9/2026 | 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded inputs.filename value is passed to path.join()… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | Opensearch DashboardsAI | 18/8/2026 | 20/8/2026 | Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mapsteps UG Ultimate Dashboard PROAI | 18/8/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Dashboard Ultimate Dashboard Pro ultimate-dashboard-pro allows DOM-Based XSS.This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mangboard Mang Board WPAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.3.4 versions. | |
| Pendiente de análisis | Alta (8.8) | 0.60% | — | Opendatahub ODH DashboardAI | 10/8/2026 | 14/8/2026 | A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like… | |
| Pendiente de análisis | Alta (8.8) | 0.52% | — | Redhat ODH DashboardAI | 10/8/2026 | 28/9/2026 | A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrary role, including highly privileged ones like `cluster-admin`. This can lead to… | |
| Aplazada | Crítica (9.8) | 0.73% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root. | |
| Aplazada | Crítica (9.8) | 10% | 💥 Exploit | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WgdashboardAI | 6/8/2026 | 3/9/2026 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses. | |
| Aplazada | Alta (8.1) | 0.87% | — | Wpmudev Wpmu DEV DashboardAI | 6/8/2026 | 12/8/2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signature verified by… | |
| Aplazada | Alta (7.3) | 0.41% | — | Material DashboardAI | 5/8/2026 | 12/8/2026 | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks… | |
| Aplazada | Media (4.3) | 0.27% | — | FluentboardsAI | 2/8/2026 | 26/8/2026 | The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions… | |
| Analizada | Alta (8.8) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message… | |
| Analizada | Crítica (9.3) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the… | |
| Aplazada | Alta (8.4) | 0.41% | — | KanboardAI | 30/7/2026 | 31/7/2026 | Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through the web link creation feature, causing… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (6.1) | 0.25% | — | Regularlabs Keyboard ShortcutsAI | 23/7/2026 | 23/7/2026 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. | |
| Pendiente de análisis | Alta (8.8) | 0.46% | — | Redhat Openshift AIAIRedhat ODH DashboardAI | 23/7/2026 | 30/9/2026 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the… | |
| Aplazada | Media (6.8) | 0.21% | — | Axivion DashboardAI | 16/7/2026 | 16/7/2026 | An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect to the application's own origin, so a user who follows a crafted login link can be sent to an untrusted external site after… |