Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.49% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (8.8) | 1.1% | — | Cisco Nexus Dashboard Fabric Controller | 2/10/2024 | 17/6/2026 | A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user authorization and insufficient validation of… | |
| Analizada | Media (5.9) | 0.30% | — | Cisco Nexus Dashboard Orchestrator | 2/10/2024 | 17/6/2026 | This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.… | |
| Aplazada | Media (4.8) | 0.37% | — | Metronic Admin Dashboard TemplateAI | 30/9/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. | |
| Analizada | Alta (8.8) | 0.71% | — | Buffercode Frontend Dashboard | 10/9/2024 | 17/6/2026 | The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Analizada | Alta (8.8) | 0.21% | — | Naiches Dark Mode FOR WP Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3. | |
| Analizada | Baja (3.5) | 0.18% | — | Analytify - Google Analytics Dashboard | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1. | |
| Aplazada | Media (6.1) | 0.26% | — | Opensearch DashboardsAIOpensearch SecurityAI | 23/8/2024 | 17/6/2026 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and… | |
| Aplazada | Media (4.2) | 0.17% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 16/8/2024 | 17/6/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download… | |
| Aplazada | Media (6.5) | 0.26% | — | Jeroensormani WP Dashboard NotesAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11. | |
| Aplazada | Media (5.9) | 0.27% | — | Webstix Admin Dashboard RSS FeedAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webstix Admin Dashboard RSS Feed allows Stored XSS.This issue affects Admin Dashboard RSS Feed: from n/a through 3.1. | |
| Modificada | Media (4.3) | 0.34% | — | Wprepublic Hide Dashboard Notifications | 21/6/2024 | 17/6/2026 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to… | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Telemetry Dashboard | 13/6/2024 | 17/6/2026 | Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information disclosure. | |
| Modificada | Media (6.1) | 0.37% | — | Plugin-planet Dashboard Widgets Suite | 13/6/2024 | 17/6/2026 | The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Modificada | Alta (8.8) | 0.33% | — | Arwebdesign Dashboard To-do List | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.2.0. | |
| Modificada | Alta (8.8) | 0.20% | — | Analytify - Google Analytics Dashboard | 8/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3. | |
| Aplazada | Baja (3.7) | 0.30% | — | Davidvongries Ultimate DashboardAI | 4/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate Dashboard: from n/a through 3.7.10. | |
| Aplazada | Media (6.5) | 0.67% | — | Wpfactory Download Plugins AND Themes From DashboardAI | 22/5/2024 | 17/6/2026 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server. | |
| Aplazada | Media (5.4) | 0.25% | — | 3DS 3ddashboardAI3dswymerAI | 17/5/2024 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code. | |
| Modificada | Media (5.4) | 0.29% | — | Analytify - Google Analytics Dashboard | 2/5/2024 | 17/6/2026 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for… | |
| Modificada | Media (5.3) | 0.43% | — | Analytify - Google Analytics Dashboard | 2/5/2024 | 17/6/2026 | The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.20% | — | Wprepublic Hide Dashboard NotificationsAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP Republic Hide Dashboard Notifications.This issue affects Hide Dashboard Notifications: from n/a through 1.2.3. | |
| Aplazada | Alta (7.5) | 0.68% | — | Buffercode Frontend DashboardAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2. | |
| Analizada | Media (5.5) | 0.22% | — | Dell Telemetry Dashboard | 24/4/2024 | 17/6/2026 | Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability to read sensitive proxy settings information. |