Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.30%—Marbella Kr8s Dashcam FFAI28/7/202517/6/2026
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is written onto the SD card in cleartext automatically. An attacker with temporary access to the dashcam can switch the SD card to steal this password.
AnalizadaMedia (6.1)0.56%💥 ExploitLinuxserver Heimdall Application Dashboard27/7/202517/6/2026
LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
AplazadaMedia (4.3)0.27%—Morten Dalgaard Johansen Dashboard Widget SidebarAI27/6/202517/6/2026
Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Widget Sidebar: from n/a through <= 1.2.3.
AplazadaMedia (4.3)0.14%—WP Sliding Login Dashboard PanelAI13/6/202517/6/2026
The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the wp_sliding_panel_user_options() function. This makes it possible for unauthenticated attackers to update plugin…
AplazadaBaja (1.2)0.30%—RedashAI9/6/202517/6/2026
A vulnerability was found in Redash up to 10.1.0/25.1.0. It has been rated as problematic. This issue affects the function run_query of the file /query_runner/python.py of the component getattr Handler. The manipulation leads to sandbox issue. The complexity of an attack is rather high. The exploitation is known to be…
AplazadaMedia (6.5)0.25%—Buffercode Frontend DashboardAI6/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through <= 2.2.8.
AnalizadaAlta (8.7)0.43%—Cisco Nexus Dashboard4/6/202517/6/2026
A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a…
AnalizadaMedia (6.1)0.27%—Gearside Developer Dashboard30/5/202517/6/2026
The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (6.8)0.65%—RadashiAI27/5/202517/6/2026
Radashi is a TypeScript utility toolkit. Prior to version 12.5.1, the set function within the Radashi library is vulnerable to prototype pollution. If an attacker can control parts of the path argument to the set function, they could potentially modify the prototype of all objects in the JavaScript runtime, leading to…
AplazadaCrítica (9.8)0.59%—Themeton DashAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in themeton Dash allows Object Injection. This issue affects Dash: from n/a through 1.3.
AplazadaMedia (6.5)0.20%—Uncannyowl Uncanny Toolkit FOR LearndashAI16/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash uncanny-learndash-toolkit allows Stored XSS.This issue affects Uncanny Toolkit for LearnDash: from n/a through <= 3.7.0.2.
AnalizadaAlta (7.5)0.53%—Jeroensormani WP Dashboard Notes15/5/202517/6/2026
The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users.
AnalizadaMedia (5.4)0.84%💥 ExploitDeryckoe Logdash Activity LOG15/5/202517/6/2026
The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based…
AplazadaAlta (8.8)0.43%—Buffercode Frontend DashboardAI13/5/202517/6/2026
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_admin_setting_form_function() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin’s…
AplazadaAlta (8.8)0.45%—Buffercode Frontend DashboardAI13/5/202517/6/2026
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_request() function in versions 1.0 to 2.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to control where the plugin sends outgoing emails. By…
AplazadaMedia (5.8)2.0%💥 ExploitPwsdashboard Personal Weather Station DashboardAI7/5/202517/6/2026
Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in the test parameter to /others/_test.php, as demonstrated by reading the server's private SSL key in cleartext.
AplazadaCrítica (9.8)0.59%—Buffercode Frontend DashboardAI7/5/202517/6/2026
The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the fed_wp_ajax_fed_login_form_post() function in versions 1.0 to 2.2.6. This makes it possible for unauthenticated attackers to reset the administrator’s email and password, and elevate their…
AnalizadaMedia (5.3)0.53%💥 PoCCode-projects News Publishing Site Dashboard27/4/202517/6/2026
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-category.php of the component Edit Category Page. The manipulation of the argument category_image leads to unrestricted upload. The attack may be…
AnalizadaMedia (5.3)0.53%—Code-projects News Publishing Site Dashboard27/4/202517/6/2026
A vulnerability was found in codeprojects News Publishing Site Dashboard 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /api.php. The manipulation of the argument cat_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AplazadaCrítica (9.3)0.37%—Buffercode Frontend DashboardAI24/4/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows SQL Injection.This issue affects Frontend Dashboard: from n/a through <= 2.2.5.
AplazadaMedia (5.8)0.29%—Jidaikobo DashiAI17/4/202517/6/2026
Missing Authorization vulnerability in jidaikobo Dashi dashi allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dashi: from n/a through <= 3.1.8.
AplazadaAlta (7.1)0.15%—Swedish BOY Dashboard NotepadsAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.This issue affects Dashboard Notepads: from n/a through <= 1.2.1.
AplazadaMedia (6.5)0.38%—Wpseek Wordpress Dashboard TweeterAI17/4/202517/6/2026
Missing Authorization vulnerability in wpseek WordPress Dashboard Tweeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WordPress Dashboard Tweeter: from n/a through 1.3.2.
AplazadaMedia (6.5)0.27%—Think201 Data DashAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash data-dash allows Stored XSS.This issue affects Data Dash: from n/a through <= 1.2.3.
AnalizadaBaja (3.5)0.27%—Davidvongries Ultimate Dashboard17/4/202517/6/2026
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Orbitaley — Vulnerabilidades