Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.35%—Jenkins Deployment Dashboard13/12/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs.
ModificadaMedia (4.3)0.44%—Bowo System Dashboard7/12/202317/6/2026
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (4.3)0.47%—Bowo System Dashboard7/12/202317/6/2026
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,…
ModificadaMedia (4.3)0.43%—Bowo System Dashboard7/12/202317/6/2026
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,…
ModificadaMedia (4.3)0.44%—Bowo System Dashboard7/12/202317/6/2026
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (4.3)0.47%—Bowo System Dashboard7/12/202317/6/2026
The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
ModificadaMedia (4.8)0.38%—Davidvongries Ultimate Dashboard22/11/202317/6/2026
The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject…
ModificadaMedia (4.8)0.35%—Properfraction Admin BAR & Dashboard Access Control6/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions.
ModificadaMedia (6.5)0.52%—IBM Cognos Dashboards ON Cloud PAK FOR Data22/10/202317/6/2026
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482.
ModificadaAlta (7.5)0.36%—IBM Cognos Dashboards ON Cloud PAK FOR Data22/10/202317/6/2026
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736.
ModificadaAlta (7.5)0.36%—IBM Cognos Dashboards ON Cloud PAK FOR Data22/10/202317/6/2026
IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730.
ModificadaMedia (6.1)0.33%—Extendwings Opcache Dashboard18/10/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.
ModificadaAlta (8.8)0.59%—Wazuh-dashboardWazuh-kibana-app9/10/202317/6/2026
Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their…
ModificadaAlta (7.5)0.47%—Opendatahub Open Data HUB DashboardRedhat Openshift Data Science4/10/202317/6/2026
A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret.
ModificadaCrítica (9.8)1.2%—Open-falcon Dashboard11/8/202317/6/2026
An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.
ModificadaAlta (7.5)0.80%—Dietpi-dashboard Project Dietpi-dashboard27/7/202317/6/2026
DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be waiting for a handshake, and will stay this way indefinitely until a handshake…
ModificadaMedia (4.8)0.47%—Ultimate Dashboard Project Ultimate Dashboard19/6/202317/6/2026
The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (7.8)32%—Schneider-electric Igss Dashboard14/6/202317/6/2026
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file.
ModificadaMedia (5.4)0.37%—Monsterinsights Google Analytics Dashboard18/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.
ModificadaMedia (4.8)0.37%—Plugin-planet Dashboard Widget Suite6/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions.
ModificadaMedia (5.5)0.19%—HP OneviewHPE Oneview Global Dashboard25/4/202317/6/2026
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
ModificadaAlta (7.2)1.3%—Pwsdashboard Personal Weather Station Dashboard25/4/202317/6/2026
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a…
ModificadaMedia (5.5)0.18%—HPE Oneview Global Dashboard14/4/202317/6/2026
An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials
ModificadaMedia (4.8)0.37%—Announce From THE Dashboard Project Announce From THE Dashboard7/4/202317/6/2026
Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions.
ModificadaMedia (5.3)0.44%—Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server21/3/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data…