Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.49%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this…
AnalizadaMedia (5.4)0.36%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (8.8)1.1%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.   This vulnerability is due to improper user authorization and insufficient validation of…
AnalizadaMedia (5.9)0.30%—Cisco Nexus Dashboard Orchestrator2/10/202417/6/2026
This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Policy Infrastructure Controller (APIC), Cisco Cloud Network Controller (CNC), and Cisco Nexus Dashboard only when a new site is added or an existing one is reregistered.…
AplazadaMedia (4.8)0.37%—Metronic Admin Dashboard TemplateAI30/9/202417/6/2026
A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.
AnalizadaAlta (8.8)0.71%—Buffercode Frontend Dashboard10/9/202417/6/2026
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above,…
AnalizadaAlta (8.8)0.21%—Naiches Dark Mode FOR WP Dashboard26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through 1.2.3.
AnalizadaBaja (3.5)0.18%—Analytify - Google Analytics Dashboard26/8/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.
AplazadaMedia (6.1)0.26%—Opensearch DashboardsAIOpensearch SecurityAI23/8/202417/6/2026
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and…
AplazadaMedia (4.2)0.17%—Download Plugins AND Themes IN ZIP From DashboardAI16/8/202417/6/2026
The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download…
AplazadaMedia (6.5)0.26%—Jeroensormani WP Dashboard NotesAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Sormani WP Dashboard Notes allows Stored XSS.This issue affects WP Dashboard Notes: from n/a through 1.0.11.
AplazadaMedia (5.9)0.27%—Webstix Admin Dashboard RSS FeedAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webstix Admin Dashboard RSS Feed allows Stored XSS.This issue affects Admin Dashboard RSS Feed: from n/a through 3.1.
ModificadaMedia (4.3)0.34%—Wprepublic Hide Dashboard Notifications21/6/202417/6/2026
The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'warning_notices_settings' function in all versions up to, and including, 1.3. This makes it possible for authenticated attackers, with contributor access and above, to…
ModificadaMedia (5.5)1.2%—Microsoft Telemetry Dashboard13/6/202417/6/2026
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability leading to information disclosure.
ModificadaMedia (6.1)0.37%—Plugin-planet Dashboard Widgets Suite13/6/202417/6/2026
The Dashboard Widgets Suite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 3.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (8.8)0.33%—Arwebdesign Dashboard To-do List10/6/202417/6/2026
Missing Authorization vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.2.0.
ModificadaAlta (8.8)0.20%—Analytify - Google Analytics Dashboard8/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3.
AplazadaBaja (3.7)0.30%—Davidvongries Ultimate DashboardAI4/6/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate Dashboard: from n/a through 3.7.10.
AplazadaMedia (6.5)0.67%—Wpfactory Download Plugins AND Themes From DashboardAI22/5/202417/6/2026
Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server.
AplazadaMedia (5.4)0.25%—3DS 3ddashboardAI3dswymerAI17/5/202417/6/2026
A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code.
ModificadaMedia (5.4)0.29%—Analytify - Google Analytics Dashboard2/5/202417/6/2026
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for…
ModificadaMedia (5.3)0.43%—Analytify - Google Analytics Dashboard2/5/202417/6/2026
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated…
AplazadaMedia (4.3)0.20%—Wprepublic Hide Dashboard NotificationsAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Republic Hide Dashboard Notifications.This issue affects Hide Dashboard Notifications: from n/a through 1.2.3.
AplazadaAlta (7.5)0.68%—Buffercode Frontend DashboardAI24/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in vinoth06. Frontend Dashboard.This issue affects Frontend Dashboard: from n/a through 2.2.2.
AnalizadaMedia (5.5)0.22%—Dell Telemetry Dashboard24/4/202417/6/2026
Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability to read sensitive proxy settings information.
Orbitaley — Vulnerabilidades