Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.29%—Hitachivantara Pentaho Data IntegrationAIHitachivantara Pentaho Analytics Community Dashboard FrameworkAI15/12/20257/10/2026
Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, including 9.3.0.x and 8.3.x display the full server stack trace when encountering an error within the GetCdfResource servlet.
AplazadaAlta (8.8)0.43%—Pentaho Data IntegrationAIPentaho Analytics Community Dashboard EditorAI15/12/20257/10/2026
Pentaho Data Integration and Analytics Community Dashboard Editor plugin versions before 10.2.0.4, including 9.3.0.x and 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.
AplazadaAlta (8.8)0.80%—Player LeaderboardAI12/12/20257/10/2026
The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This is due to the plugin using an unsanitized user-supplied value from the shortcode's 'mode' attribute in a call to include() without proper path…
AplazadaMedia (5.3)0.37%—FlatboardAI11/12/202517/6/2026
Flatboard 3.2 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts in forum information fields. Attackers can insert JavaScript payloads that execute when other users view the forum, potentially stealing session cookies and executing client-side…
AplazadaAlta (7.6)0.24%—Aksis Computer Services AND Consulting INC AxonboardAI11/12/202517/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc. AxOnboard allows Exploitation of Trusted Identifiers. This issue affects AxOnboard: from 3.2.0 before 3.3.0.
AnalizadaAlta (8.9)0.41%—Laradashboard Lara Dashboard4/12/202517/6/2026
LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically…
AnalizadaAlta (8.9)1.3%—Remotecontrolio Remote Keyboard Desktop4/12/202517/6/2026
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.
AplazadaAlta (8.8)0.68%—Airkeyboard IOSAI4/12/202517/6/2026
AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.
AplazadaMedia (6.5)0.46%—Openstack Mistral-dashboardAI26/11/202517/6/2026
The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.
AplazadaMedia (5.3)0.27%—Chamber Dashboard Business DirectoryAI25/11/202517/6/2026
The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing capability check on the cdash_watch_for_export() function in all versions up to, and including, 3.3.11. This makes it possible for unauthenticated attackers to export business directory information,…
AplazadaMedia (6.1)0.26%—Bestwebsoft JOB BoardAI25/11/202517/6/2026
The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.2.1. This is due to the plugin storing the entire unsanitized `$_GET` superglobal array directly into the database via `update_user_meta()` when users save search results, and later…
AplazadaMedia (6.1)0.21%—Mang Board WPAI8/11/202517/6/2026
The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaMedia (6.1)0.25%—Matiasdesuu Thinkdashboard6/11/202517/6/2026
ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, there is a stored Cross-Site Scripting (XSS) vulnerability in the dashboard, which can exploited when a user clicks on a malicious bookmark, made vulnerable by the lack of scheme filtering. This is…
AnalizadaMedia (6.1)0.28%—Matiasdesuu Thinkdashboard6/11/202517/6/2026
ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an attacker can upload any file they wish to the /data directory of the web application via the backup import feature. When importing a backup, an attacker can first choose a .zip file to bypass the…
AnalizadaMedia (5.3)0.35%—Matiasdesuu Thinkdashboard6/11/202517/6/2026
ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contain a Blind Server-Side Request Forgery (SSRF) vulnerability, in its `/api/ping?url= endpoint`. This allows an attacker to make arbitrary requests to internal or external hosts. This can include…
AplazadaMedia (6.3)0.26%—Discussion BoardAI25/10/202517/6/2026
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.5.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible…
AplazadaAlta (8.7)0.49%—Karmada DashboardAI24/10/202517/6/2026
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce…
AnalizadaMedia (6.1)0.28%—SIR Gnuboard23/10/202517/6/2026
Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via crafted c_id parameter in bbs/view_comment.php.
AnalizadaMedia (6.5)0.23%—SIR Gnuboard23/10/202517/6/2026
gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.
AplazadaAlta (7.5)0.39%—Presstigers Simple JOB BoardAI22/10/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in PressTigers Simple Job Board simple-job-board allows Retrieve Embedded Sensitive Data.This issue affects Simple Job Board: from n/a through <= 2.13.7.
AplazadaMedia (6.9)1.1%—Wikimedia Mediawiki Springboard ExtensionAI21/10/202517/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.
AnalizadaMedia (6.9)1.8%💥 ExploitThingsboard17/10/202514/7/2026
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes the SVG file in a way that parses external references, it may initiate unintended…
ModificadaMedia (6.2)0.38%—Thingsboard17/10/202517/6/2026
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images…
AnalizadaMedia (6.5)0.29%—Myupb Ultimate PHP Board16/10/202517/6/2026
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
AnalizadaMedia (6.1)0.27%—Myupb Ultimate PHP Board16/10/202517/6/2026
Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.