Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.19% | — | Kanboard | 10/2/2026 | 17/6/2026 | Kanboard is project management software focused on Kanban methodology. Prior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists in the ProjectPermissionController within the Kanboard application. The application fails to strictly enforce the application/json Content-Type for the changeUserRole action.… | |
| Aplazada | Crítica (9.3) | 0.68% | — | Sunfounder Pironman DashboardAI | 1/2/2026 | 14/7/2026 | SunFounder Pironman Dashboard (pm_dashboard) version 1.3.13 and prior contain a path traversal vulnerability in the log file API endpoints. An unauthenticated remote attacker can supply traversal sequences via the filename parameter to read and delete arbitrary files. Successful exploitation can disclose sensitive… | |
| Analizada | Media (6.1) | 0.20% | — | Naver Billboard.js | 28/1/2026 | 17/6/2026 | billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding. | |
| Aplazada | Crítica (9.2) | 0.29% | — | Cardboardpowered CardboardAI | 27/1/2026 | 17/6/2026 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before 1.21.4. | |
| Aplazada | Media (5.4) | 0.30% | — | Fluent BoardsAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentBoards: from n/a through <= 1.91.1. | |
| Aplazada | Alta (7.3) | 0.27% | — | OnboardliteAI | 19/1/2026 | 17/6/2026 | OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site scripting vulnerability that can be rendered to an admin when they attempt to… | |
| Aplazada | Alta (7.1) | 0.16% | — | Dashboard BuilderAI | 14/1/2026 | 17/6/2026 | The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.7. This is due to missing nonce validation on the settings handler in dashboardbuilder-admin.php. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.5) | 0.20% | — | Clevo Hotkey ClipboardAI | 13/1/2026 | 17/6/2026 | Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables… | |
| Aplazada | Media (5.3) | 0.21% | — | Ideabox Creations Dashboard Welcome FOR Beaver BuilderAIFastlinemedia Beaver BuilderAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <= 1.0.8. | |
| Analizada | Crítica (9.1) | 0.49% | — | Kanboard | 8/1/2026 | 17/6/2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below is vulnerable to a critical authentication bypass when REVERSE_PROXY_AUTH is enabled. The application blindly trusts HTTP headers for user authentication without verifying the request originated from a trusted reverse… | |
| Analizada | Media (5.3) | 0.40% | — | Kanboard | 8/1/2026 | 17/6/2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below have an LDAP Injection vulnerability in the LDAP authentication mechanism. User-supplied input is directly substituted into LDAP search filters without proper sanitization, allowing attackers to enumerate all LDAP users,… | |
| Analizada | Media (6.1) | 0.31% | — | Kanboard | 8/1/2026 | 17/6/2026 | Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filter_var($url,… | |
| Aplazada | Media (4.7) | 0.28% | — | Sharethis Dashboard FOR Google AnalyticsAI | 7/1/2026 | 17/6/2026 | The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.4. This is due to the Google Analytics client_ID and client_secret being stored in plaintext in the publicly visible plugin source. This can allow unauthenticated… | |
| Aplazada | Media (5.9) | 0.17% | — | Janhenckels Wp-dashboard-beaconAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janhenckens Dashboard Beacon wp-dashboard-beacon allows Stored XSS.This issue affects Dashboard Beacon: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Webbuilder143 Sticky Notes FOR WP DashboardAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4. | |
| Aplazada | Media (4.3) | 0.18% | — | Marketing Fire Wp-discussion-boardAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Marketing Fire Discussion Board wp-discussion-board allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Discussion Board: from n/a through <= 2.5.7. | |
| Aplazada | Alta (8.5) | 0.24% | — | Ross Video DashboardAI | 24/12/2025 | 17/6/2026 | Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files due to improper permission settings. Attackers can exploit the 'M' or 'C' flags for 'Authenticated Users' group to replace the DashBoard.exe binary with a malicious executable. | |
| Aplazada | Alta (8.6) | 0.48% | — | WpjobboardAI | 24/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPJobBoard allows Blind SQL Injection.This issue affects WPJobBoard: from n/a through 5.9.0. | |
| Aplazada | Media (5.9) | 0.21% | — | Brownbagmarketing Greenhouse JOB BoardAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing Greenhouse Job Board greenhouse-job-board allows DOM-Based XSS.This issue affects Greenhouse Job Board: from n/a through <= 2.7.3. | |
| Aplazada | Alta (7.1) | 0.22% | — | Schiocco Support BoardAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through < 3.8.7. | |
| Aplazada | Media (4.3) | 0.12% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 17/12/2025 | 28/9/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for… | |
| Aplazada | Alta (7) | 0.23% | — | Asus MotherboardsAIIntel B460 ChipsetAIIntel B560 ChipsetAIIntel B660 ChipsetAI+10 | 17/12/2025 | 7/10/2026 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760, H410, H510, H610, H470, Z590, Z690, Z790, W480, W680 series chipsets. Exploitation requires physical access to internal expansion slots to install a specially crafted device and supporting software… | |
| Aplazada | Alta (7) | 0.35% | — | MSI MotherboardAI | 17/12/2025 | 17/6/2026 | Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded. | |
| Aplazada | Alta (7) | 0.35% | — | Asrock MotherboardAIAsrockrack MotherboardAIAsrocind MotherboardAI | 17/12/2025 | 7/10/2026 | Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel… | |
| Aplazada | Alta (7) | 0.35% | — | Gigabyte MotherboardAI | 17/12/2025 | 7/10/2026 | Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not properly enabled, unauthenticated physical attackers can use a DMA-capable PCIe device to read and write arbitrary physical memory before the OS kernel and its security features are loaded. |