Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.31% | — | Fastflow Fast Flow DashboardAI | 25/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fastflow Fast Flow fast-flow-dashboard allows Reflected XSS.This issue affects Fast Flow: from n/a through <= 1.2.16. | |
| Modificada | Crítica (9.8) | 0.75% | — | Yitechnology YI CAR Dashcam Firmware | 24/2/2025 | 17/6/2026 | Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API commands. API commands can also be made to make unauthorized modifications to the device settings, such as disabling recording, disabling sounds, factory reset. | |
| Analizada | Media (5.4) | 0.31% | — | Covertnine C9 Admin Dashboard | 21/2/2025 | 17/6/2026 | The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Modificada | Alta (8.8) | 0.33% | — | Analytify - Google Analytics Dashboard | 17/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.5.0. | |
| Aplazada | Alta (7.1) | 0.28% | — | Think201 Data DashAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Data Dash data-dash allows Reflected XSS.This issue affects Data Dash: from n/a through <= 1.2.3. | |
| Aplazada | Alta (7.1) | 0.31% | — | Kvvaradha KV Compose Email From DashboardAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kvvaradha Kv Compose Email From Dashboard kv-send-email-from-admin allows Reflected XSS.This issue affects Kv Compose Email From Dashboard: from n/a through <= 1.1. | |
| Aplazada | Alta (7.1) | 0.31% | — | Mike Martel Live DashboardAI | 14/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mike Martel Live Dashboard live-dashboard allows Reflected XSS.This issue affects Live Dashboard: from n/a through <= 0.3.3. | |
| Modificada | Alta (7.5) | 0.58% | — | Learndash | 12/2/2025 | 17/6/2026 | An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) via excessive file uploads. | |
| Analizada | Media (5.4) | 0.33% | — | Learndash | 12/2/2025 | 17/6/2026 | LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body class. | |
| Analizada | Media (5.4) | 0.33% | — | Learndash | 12/2/2025 | 17/6/2026 | LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content class. | |
| Aplazada | Media (6.4) | 0.60% | 💥 PoC | Opensearch Dashboards-reportingAIOpensearchAI | 12/2/2025 | 17/6/2026 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer. | |
| Aplazada | Alta (7.1) | 0.14% | — | Victor Barkalov Custom Links ON Admin Dashboard ToolbarAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This issue affects Custom Links On Admin Dashboard Toolbar: from n/a through <= 3.3. | |
| Aplazada | Alta (7.1) | 0.33% | — | Dashed-slug Bitcoin AND Altcoin WalletsAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashed-slug.net Bitcoin and Altcoin Wallets wallets allows Reflected XSS.This issue affects Bitcoin and Altcoin Wallets: from n/a through <= 6.3.1. | |
| Modificada | Media (6.1) | 0.40% | — | Bowo System Dashboard | 30/1/2025 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.31% | — | Learndash LMSAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in LearnDash LearnDash LMS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnDash LMS: from n/a through 4.20.0.1. | |
| Aplazada | Media (5.4) | 0.31% | — | Exactmetrics Google Analytics Dashboard FOR WPAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi ExactMetrics google-analytics-dashboard-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ExactMetrics: from n/a through <= 8.1.0. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 24/1/2025 | 17/6/2026 | IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion. | |
| Aplazada | Alta (7.1) | 0.26% | — | Flx0 FLX Dashboard GroupsAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flx0 FLX Dashboard Groups flx-dashboard-groups allows Reflected XSS.This issue affects FLX Dashboard Groups: from n/a through <= 0.0.7. | |
| Aplazada | Media (5.4) | 0.48% | — | Chandrika Guntur Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8. | |
| Aplazada | Alta (7.1) | 0.20% | — | Taras Dashkevych Error-notificationAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taras Dashkevych Error Notification error-notification allows Cross Site Request Forgery.This issue affects Error Notification: from n/a through <= 0.2.7. | |
| Aplazada | Media (6.4) | 0.34% | — | Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.28% | — | Faizaan Gagan Course Migration FOR LearndashAI | 15/1/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Faizaan Gagan Course Migration for LearnDash allows Server Side Request Forgery.This issue affects Course Migration for LearnDash: from 1.0.2 through n/a. | |
| Analizada | Crítica (9.8) | 0.39% | — | Analytify - Google Analytics Dashboard | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3. | |
| Aplazada | Media (5.4) | 0.17% | — | Uncannyowl Uncanny Toolkit PRO FOR LearndashAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1. | |
| Aplazada | Alta (7.1) | 0.34% | — | Duogeek Custom Dashboard WidgetAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Reflected XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0. |