Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.43% | — | RPB ChessboardAI | 16/7/2026 | 18/7/2026 | The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.2) | 0.50% | — | KanboardAI | 15/7/2026 | 15/7/2026 | Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-drop endpoint) validates the caller's role on the attacker-supplied project_id but never verifies that the supplied task_id actually belongs to that project. Because task identifiers are sequential… | |
| Aplazada | Media (6.4) | 0.35% | — | Starboard Suite Reservation CalendarsAI | 11/7/2026 | 29/9/2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.8) | 0.16% | — | Samsung SemclipboardserviceAI | 10/7/2026 | 14/7/2026 | Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege. | |
| Aplazada | Media (6.1) | 0.38% | — | Mang Board WPAI | 9/7/2026 | 9/7/2026 | The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Baja (2.1) | 0.29% | — | Flask-dashboard Flask-monitoringdashboardAI | 8/7/2026 | 8/7/2026 | A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The project was… | |
| Aplazada | Media (5.3) | 0.48% | — | KanboardAI | 25/6/2026 | 14/7/2026 | Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id parameter before passing it to RememberMeSessionModel::remove, allowing authenticated users to delete other users' Remember Me sessions. Attackers can enumerate sequential session IDs and… | |
| Aplazada | Media (6.5) | 0.60% | — | CboardAI | 23/6/2026 | 5/7/2026 | SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component | |
| Pendiente de análisis | Media (5.1) | 0.49% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 24/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass network access… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | U.s. Government Accountability Office Electronic Protest Docketing SystemAICivilian Board OF Contract Appeals Electronic Docketing SystemAI | 18/6/2026 | 22/6/2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own… | |
| Aplazada | Alta (8.6) | 0.80% | — | ThingsboardAI | 17/6/2026 | 22/6/2026 | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN). | |
| Aplazada | Crítica (9.8) | 0.48% | — | Schiocco Support BoardAI | 17/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. | |
| Aplazada | Crítica (9.8) | 0.77% | — | ThingsboardAI | 15/6/2026 | 17/6/2026 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass… | |
| Analizada | Crítica (9.8) | 0.62% | — | Aqara Board Service | 12/6/2026 | 9/7/2026 | The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's HiveMQ broker without authentication. This is an instance of "CWE-306: Missing Authentication for Critical Function" and has an estimated CVSS ofCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L (8.6… | |
| Aplazada | Media (4.3) | 0.42% | — | Alba BoardAI | 5/6/2026 | 23/7/2026 | The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to access… | |
| Aplazada | Baja (2.3) | 0.35% | — | ThingsboardAI | 26/5/2026 | 23/7/2026 | A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the component YAML Handler. This manipulation causes code injection. It is possible to initiate the attack remotely. The attack's complexity is rated… | |
| Analizada | Crítica (9.3) | 2.4% | 💥 Exploit | Wgdashboard | 12/5/2026 | 17/6/2026 | WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2. | |
| Aplazada | Alta (8.8) | 0.23% | — | E-kalite Software Turboard For-sAI | 12/5/2026 | 17/6/2026 | Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. | |
| Aplazada | Crítica (9.2) | 0.23% | — | Ingecon SUN EMS BoardAI | 12/5/2026 | 17/6/2026 | Insecure generation of credentials in the local SAT (Technical Support) access functionality of the Ingecon Sun EMS Board. The vulnerability arose because the secret access credentials were not based on a secure cryptographic scheme, but rather on a weak hashing algorithm, which could allow an attacker to carry out a… | |
| Analizada | Media (4.9) | 0.42% | — | V2board | 1/5/2026 | 17/6/2026 | SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($sort, $sortType) without validation. An authenticated admin can sort users by any database column including password, remember_token, and… | |
| Analizada | Alta (7.5) | 0.43% | — | V2board | 1/5/2026 | 17/6/2026 | Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmission. The token appears in URLs such as /api/v1/server/UniProxy/user?token=SECRET, causing it to be recorded in web server… | |
| Analizada | Media (4.8) | 0.29% | — | V2board | 1/5/2026 | 17/6/2026 | Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. An admin can inject arbitrary JavaScript via the saveThemeConfig API. All site visitors execute the payload, enabling cookie theft,… | |
| Aplazada | Media (4.3) | 0.18% | — | Ultimate DashboardAI | 1/5/2026 | 17/6/2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.14. This is due to a flawed nonce validation conditional in the 'handle_module_actions' function. This makes it possible for unauthenticated attackers to toggle plugin modules on or off via… | |
| Aplazada | Alta (7.6) | 0.46% | — | 4gaboards 4GA BoardsAI | 24/4/2026 | 17/6/2026 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once imported, the file can be downloaded through the… | |
| Aplazada | Media (5.3) | 0.33% | — | 4GA BoardsAI | 24/4/2026 | 17/6/2026 | 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a valid username/email… |