Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.30% | — | WP Dashboard ChatAI | 15/10/2025 | 17/6/2026 | The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.22% | — | Pickplugins JOB Board ManagerAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Board Manager job-board-manager allows DOM-Based XSS.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Media (4.3) | 0.20% | 💥 PoC | Bowo System DashboardAI | 26/9/2025 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.20. This is due to missing nonce validation on the sd_toggle_logs() function. This makes it possible for unauthenticated attackers to toggle critical logging settings including Page Access… | |
| Aplazada | Media (6.5) | 0.21% | — | Codefish Pinterest Pinboard WidgetAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codefish Pinterest Pinboard Widget pinterest-pinboard-widget allows Stored XSS.This issue affects Pinterest Pinboard Widget: from n/a through <= 1.0.7. | |
| Aplazada | Media (4.3) | 0.16% | — | Stephanieleary Dashboard NotepadAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Notepad dashboard-notepad allows Cross Site Request Forgery.This issue affects Dashboard Notepad: from n/a through <= 1.42. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Hossein Material DashboardAI | 9/9/2025 | 17/6/2026 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.This issue affects Material Dashboard: from n/a through <= 1.4.6. | |
| Aplazada | Baja (3.8) | 0.25% | — | Pickplugins JOB Board ManagerAI | 5/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Baja (2.3) | 0.42% | — | Ckeditor5AICkeditor5-clipboardAI | 4/9/2025 | 17/6/2026 | CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be triggered by a specific user action (leading to unauthorized JavaScript… | |
| Analizada | Media (5) | 0.30% | — | Cisco Nexus Dashboard | 27/8/2025 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. This vulnerability exists because of missing authorization… | |
| Analizada | Media (5.4) | 0.26% | — | Cisco Nexus Dashboard | 27/8/2025 | 17/6/2026 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to view sensitive information or upload and modify files on an affected device. This vulnerability exists because of missing authorization… | |
| Analizada | Alta (7.2) | 0.59% | — | Cisco Nexus Dashboard | 27/8/2025 | 17/6/2026 | A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. This vulnerability is due to insufficient validation of the contents of a backup file. An attacker with valid Administrator credentials… | |
| Aplazada | Media (5.1) | 0.32% | — | Influx Initiative OnboardliteAI | 20/8/2025 | 17/6/2026 | OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft,… | |
| Aplazada | Alta (8.1) | 0.66% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Schiocco Support Board supportboard allows PHP Local File Inclusion.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Aplazada | Alta (7.1) | 0.24% | — | Schiocco Support BoardAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Schiocco Support Board supportboard allows Reflected XSS.This issue affects Support Board: from n/a through <= 3.8.0. | |
| Aplazada | Alta (8.8) | 0.18% | — | Dexignzone Jobzilla - JOB Board Wordpress ThemeAI | 20/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme jobzilla allows Privilege Escalation.This issue affects JobZilla - Job Board WordPress Theme: from n/a through <= 2.0. | |
| Analizada | Baja (2.1) | 0.30% | — | Thingsboard | 17/8/2025 | 17/6/2026 | A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.36% | — | Kanboard | 12/8/2025 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does not validate whether the task_id parameter is a valid task id, nor does it check for path traversal. As a result, a malicious actor could write a file anywhere on the… | |
| Analizada | Alta (7.2) | 0.93% | — | Kanboard | 12/8/2025 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"] field in the project_activities table.… | |
| Analizada | Media (6.1) | 0.56% | 💥 Exploit | Linuxserver Heimdall Application Dashboard | 27/7/2025 | 17/6/2026 | LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter. | |
| Analizada | Baja (2) | 0.25% | — | SIR Gnuboard | 18/7/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Analizada | Crítica (9.8) | 0.36% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute… | |
| Analizada | Crítica (9.8) | 0.90% | — | Schiocco Support Board | 9/7/2025 | 17/6/2026 | The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete arbitrary files on the server, which can easily lead to remote code… | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php. | |
| Analizada | Media (6.1) | 0.24% | — | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component. | |
| Analizada | Media (6.1) | 0.52% | 💥 Exploit | SIR Gnuboard | 7/7/2025 | 17/6/2026 | An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php. |