Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.33% | — | Flatboard PROAI | 3/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the footer_text and announcement parameters in config.php. | |
| Aplazada | Media (5.1) | 0.33% | — | Flatboard PROAI | 3/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in versions prior to Flatboard 3.2.2 of Flatboard Pro, consisting of a stored XSS due to lack of proper validation of user input, through the replace parameter in /config.php/tags. | |
| Aplazada | Media (4.3) | 0.27% | — | Morten Dalgaard Johansen Dashboard Widget SidebarAI | 27/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Morten Dalgaard Johansen Dashboard Widget Sidebar dashboard-widget-sidebar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Widget Sidebar: from n/a through <= 1.2.3. | |
| Analizada | Media (5.1) | 0.14% | — | Irohasoft Iroha Board | 26/6/2025 | 17/6/2026 | Cross-site request forgery vulnerability exists in iroha Board versions v0.10.12 and earlier. If a user accesses a specially crafted URL while being logged in to the affected product, arbitrary learning histories may be registered. | |
| Analizada | Media (5.3) | 0.24% | — | Irohasoft Iroha Board | 26/6/2025 | 17/6/2026 | Direct request ('Forced Browsing') issue exists in iroha Board versions v0.10.12 and earlier. If this vulnerability is exploited, non-public contents may be viewed by an attacker who can log in to the affected product. | |
| Analizada | Media (5.3) | 0.36% | — | Kanboard | 25/6/2025 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard is vulnerable to username enumeration and IP spoofing-based brute-force protection bypass. By analyzing login behavior and abusing trusted HTTP headers, an attacker can determine valid usernames and… | |
| Analizada | Alta (8.8) | 0.52% | — | Kanboard | 24/6/2025 | 17/6/2026 | Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.46, Kanboard allows password reset emails to be sent with URLs derived from the unvalidated Host header when the application_url configuration is unset (default behavior). This allows an attacker to craft a malicious… | |
| Analizada | Baja (1.9) | 0.26% | — | Anujk305 Notice Board System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /admin/manage-notices.php of the component Add Notice. The manipulation of the argument Title/Description leads to cross site scripting. The attack may be… | |
| Aplazada | Media (5.1) | 0.32% | — | Uyanki Board-stm32f103rc-berialAI | 15/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in uYanki board-stm32f103rc-berial up to 84daed541609cb7b46854cc6672a275d1007e295. This vulnerability affects the function heartrate1_i2c_hal_write of the file 7.Example/hal/i2c/max30100/Manual/demo2/2/heartrate1_hal.c. The manipulation of the argument num leads to… | |
| Aplazada | Media (4.3) | 0.14% | — | WP Sliding Login Dashboard PanelAI | 13/6/2025 | 17/6/2026 | The WP Sliding Login/Dashboard Panel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the wp_sliding_panel_user_options() function. This makes it possible for unauthenticated attackers to update plugin… | |
| Aplazada | Crítica (9.3) | 0.43% | — | Clickandpledge Click Pledge WpjobboardAI | 10/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from n/a through <= 25.07010000-WP6.8.1-JB5.11.5. | |
| Aplazada | Media (5.3) | 0.32% | — | Pickplugins JOB Board ManagerAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in PickPlugins Job Board Manager job-board-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Job Board Manager: from n/a through <= 2.1.60. | |
| Aplazada | Media (6.5) | 0.25% | — | Buffercode Frontend DashboardAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Frontend Dashboard frontend-dashboard allows Stored XSS.This issue affects Frontend Dashboard: from n/a through <= 2.2.8. | |
| Analizada | Media (6.9) | 0.48% | — | 1000projects Online Notice Board | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in 1000projects Online Notice Board 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument fname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.9) | 0.55% | — | Phpgurukul Notice Board System | 5/6/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.45% | — | Phpgurukul Notice Board System | 5/6/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Alta (8.7) | 0.43% | — | Cisco Nexus Dashboard | 4/6/2025 | 17/6/2026 | A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability is due to insufficient SSH host key validation. An attacker could exploit this vulnerability by performing a… | |
| Analizada | Media (5.3) | 0.40% | — | Phpgurukul Notice Board System | 4/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Notice Board System 1.0. This affects an unknown part of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 0.84% | 💥 PoC | Naver Billboard.js | 4/6/2025 | 17/6/2026 | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | |
| Analizada | Media (6.1) | 0.27% | — | Gearside Developer Dashboard | 30/5/2025 | 17/6/2026 | The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6.9) | 0.58% | — | 1000projects Online Notice Board | 29/5/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul Notice Board System | 19/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Notice Board System 1.0. It has been classified as critical. Affected is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (3.7) | 0.40% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes | |
| Analizada | Media (6.1) | 0.36% | — | Presstigers Simple JOB Board | 15/5/2025 | 17/6/2026 | In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor | |
| Analizada | Alta (7.5) | 0.53% | — | Jeroensormani WP Dashboard Notes | 15/5/2025 | 17/6/2026 | The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users. |