Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.25%—FluentboardsAI30/9/202630/9/2026
Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.
AplazadaMedia (5.3)0.21%—FluentboardsAI23/9/202623/9/2026
The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose the email addresses of a shared board's members, typically including administrators.
AplazadaBaja (3.8)0.26%—FluentboardsAI16/9/202617/9/2026
The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. This allows any member of a board to carry out manager-only actions on it, including adding or removing members and…
AplazadaBaja (3.8)0.26%—FluentboardsAI16/9/202617/9/2026
The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that appear to be authored by another user, including administrators.
AplazadaMedia (4.3)0.29%—FluentboardsAI16/9/202617/9/2026
The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, including a Subscriber with no board access, to disclose the private board memberships of arbitrary users by referencing their user ID.
Pendiente de análisisMedia (6.3)0.54%—Opensearch DashboardsAI8/9/20269/9/2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty…
AplazadaMedia (6.3)0.37%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
AplazadaAlta (8.3)0.11%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
AplazadaAlta (8.3)0.15%—PimboardsAI8/9/202611/9/2026
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
AplazadaAlta (7.2)0.54%—Fluent Boards PROAI27/8/202628/8/2026
Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.
AplazadaMedia (6.8)0.50%—Fluent Boards PROAI27/8/202628/8/2026
Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.
AplazadaCrítica (9.1)0.50%—Fluent Boards PROAI27/8/202628/8/2026
Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.
AplazadaMedia (6.5)0.22%—Fluent Boards PROAI27/8/202628/8/2026
Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.
AplazadaMedia (5.3)0.31%—Fluent Boards PROAI24/8/202624/8/2026
Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.
Pendiente de análisisMedia (6.2)0.52%—Opensearch Dashboards-observabilityAI21/8/202627/8/2026
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web…
Pendiente de análisisAlta (8.7)0.66%—Opensearch DashboardsAI20/8/202625/8/2026
Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code…
AplazadaMedia (6.5)0.44%—4gaboardsAI18/8/20269/9/2026
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows any authenticated user to enumerate account information for every user through GET /api/users and retrieve arbitrary accounts through GET /api/users/:id. The users/index and users/show actions rely only on the default…
AplazadaAlta (7.6)0.40%—4gaboardsAI18/8/20269/9/2026
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in…
AplazadaAlta (8.8)0.47%—4gaboardsAI18/8/20269/9/2026
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits…
AplazadaAlta (8.8)0.59%—4gaboardsAI18/8/20269/9/2026
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename parameter of GET /exports/:id/:filename. In server/api/controllers/boards/download.js, the decoded inputs.filename value is passed to path.join()…
Pendiente de análisisAlta (8.7)0.72%—Opensearch DashboardsAI18/8/202620/8/2026
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
AplazadaMedia (4.3)0.27%—FluentboardsAI2/8/202626/8/2026
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions…
AplazadaMedia (6.8)0.16%—Samsung SemclipboardserviceAI10/7/202614/7/2026
Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.
AplazadaAlta (7.6)0.46%—4gaboards 4GA BoardsAI24/4/202617/6/2026
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once imported, the file can be downloaded through the…
AplazadaMedia (5.3)0.33%—4GA BoardsAI24/4/202617/6/2026
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, 4ga Boards is vulnerable to user enumeration via a timing side-channel in the login endpoint (POST /api/access-tokens). When an invalid username/email is provided, the server responds immediately (~17ms average). When a valid username/email…