Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.35% | — | Jenkins Deployment Dashboard | 13/12/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to copy jobs. | |
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_db_specs() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_option_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.43% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_global_value() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Modificada | Media (4.3) | 0.44% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_php_info() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.3) | 0.47% | — | Bowo System Dashboard | 7/12/2023 | 17/6/2026 | The System Dashboard plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the sd_constants() function hooked via an AJAX action in all versions up to, and including, 2.8.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Modificada | Media (4.8) | 0.38% | — | Davidvongries Ultimate Dashboard | 22/11/2023 | 17/6/2026 | The Ultimate Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.7.7. due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Modificada | Media (4.8) | 0.35% | — | Properfraction Admin BAR & Dashboard Access Control | 6/11/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Proper Fraction LLC. Admin Bar & Dashboard Access Control plugin <= 1.2.8 versions. | |
| Modificada | Media (6.5) | 0.52% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. | |
| Modificada | Media (6.1) | 0.33% | — | Extendwings Opcache Dashboard | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions. | |
| Modificada | Alta (8.8) | 0.59% | — | Wazuh-dashboardWazuh-kibana-app | 9/10/2023 | 17/6/2026 | Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become administrator of the API, even if their… | |
| Modificada | Alta (7.5) | 0.47% | — | Opendatahub Open Data HUB DashboardRedhat Openshift Data Science | 4/10/2023 | 17/6/2026 | A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a Kubernetes secret. | |
| Modificada | Crítica (9.8) | 1.2% | — | Open-falcon Dashboard | 11/8/2023 | 17/6/2026 | An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface. | |
| Modificada | Alta (7.5) | 0.80% | — | Dietpi-dashboard Project Dietpi-dashboard | 27/7/2023 | 17/6/2026 | DietPi-Dashboard is a web dashboard for the operating system DietPi. The dashboard only allows for one TLS handshake to be in process at a given moment. Once a TCP connection is established in HTTPS mode, it will assume that it should be waiting for a handshake, and will stay this way indefinitely until a handshake… | |
| Modificada | Media (4.8) | 0.47% | — | Ultimate Dashboard Project Ultimate Dashboard | 19/6/2023 | 17/6/2026 | The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.8) | 32% | — | Schneider-electric Igss Dashboard | 14/6/2023 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that could cause an interpretation of malicious payload data, potentially leading to remote code execution when an attacker gets the user to open a malicious file. | |
| Modificada | Media (5.4) | 0.37% | — | Monsterinsights Google Analytics Dashboard | 18/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Plugin-planet Dashboard Widget Suite | 6/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions. | |
| Modificada | Media (5.5) | 0.19% | — | HP OneviewHPE Oneview Global Dashboard | 25/4/2023 | 17/6/2026 | HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens | |
| Modificada | Alta (7.2) | 1.3% | — | Pwsdashboard Personal Weather Station Dashboard | 25/4/2023 | 17/6/2026 | PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a… | |
| Modificada | Media (5.5) | 0.18% | — | HPE Oneview Global Dashboard | 14/4/2023 | 17/6/2026 | An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials | |
| Modificada | Media (4.8) | 0.37% | — | Announce From THE Dashboard Project Announce From THE Dashboard | 7/4/2023 | 17/6/2026 | Auth (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gqevu6bsiz Announce from the Dashboard plugin <= 1.5.1 versions. | |
| Modificada | Media (5.3) | 0.44% | — | Schneider-electric Custom ReportsSchneider-electric Igss DashboardSchneider-electric Igss Data Server | 21/3/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Data Server TCP interface that could allow deletion of reports from the IGSS project report directory, this would lead to loss of data when an attacker abuses this functionality. Affected Products: IGSS Data… |