Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
500 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Dash10 Oauth ServerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions. | |
| Pendiente de análisis | Media (4) | 0.14% | — | DashAI | 29/9/2026 | 29/9/2026 | A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past… | |
| Pendiente de análisis | Media (5.5) | 0.13% | — | DashAI | 29/9/2026 | 30/9/2026 | A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as *.*.*.*.*.tar.gz consume excessive CPU. | |
| Aplazada | Alta (7.1) | 0.32% | — | Nezha DashboardAI | 27/9/2026 | 28/9/2026 | Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated users with nezha:service:write scope to submit privileged task types through the service API. Attackers can deliver command execution or Agent configuration tasks to Agents within their… | |
| Aplazada | Baja (2.3) | 0.39% | — | Dashbitco Lazy HtmlAI | 25/9/2026 | 25/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_html allows mutation XSS via a parse and serialize round-trip of attacker-supplied HTML. LazyHTML.to_html/2 and LazyHTML.Tree.to_html/2 decide whether to escape an element's text from its tag name… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Dashbit Nimble ZTAAI | 24/9/2026 | 24/9/2026 | Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authentication strategy are affected. verify_token/2 in lib/nimble_zta/cloudflare.ex… | |
| Aplazada | Alta (8.2) | 0.26% | — | Divi DashAI | 23/9/2026 | 23/9/2026 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound,… | |
| Aplazada | Alta (7.1) | 0.20% | — | MythicaldashAI | 17/9/2026 | 23/9/2026 | MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embeds the payment code in the success redirect, while GET /api/stripe/processed… | |
| Pendiente de análisis | Alta (8.8) | 0.53% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.32% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Alta (8.8) | 0.28% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.8) | 0.39% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities… | |
| Pendiente de análisis | Crítica (9.9) | 0.34% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Pendiente de análisis | Crítica (9.9) | 0.27% | — | Cisco Nexus DashboardAI | 16/9/2026 | 18/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The… | |
| Aplazada | Alta (7.1) | 0.30% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged accounts can access GET /api/admin/licenses/show, POST /api/admin/licenses/store,… | |
| Aplazada | Alta (8.6) | 0.82% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation,… | |
| Aplazada | Media (5.1) | 0.24% | — | LaradashboardAI | 14/9/2026 | 23/9/2026 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user including administrators opens the stored SVG file served inline from the application… | |
| Aplazada | Baja (1.8) | 0.16% | — | Chengdu Qilu Technology LudashiAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a… | |
| Aplazada | Baja (1.8) | 0.16% | — | Chengdu Qilu Technology LudashiAI | 13/9/2026 | 15/9/2026 | A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published… | |
| Aplazada | Alta (7.1) | 0.47% | — | Lara DashboardAI | 9/9/2026 | 9/9/2026 | Lara Dashboard through 1.3.1 contains a server-side request forgery vulnerability in the POST /api/admin/builder/markdown/fetch endpoint that allows any authenticated user to fetch arbitrary URLs and read the response body. Attackers can read internal HTTP services and cloud metadata including IAM credentials by… | |
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Aplazada | Alta (8.6) | 1.1% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 10/9/2026 | Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution. | |
| Aplazada | Alta (8.6) | 0.71% | — | Laradashboard Lara DashboardAI | 7/9/2026 | 8/9/2026 | Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified… | |
| Aplazada | Media (5.3) | 0.53% | — | Lara DashboardAI | 7/9/2026 | 9/9/2026 | Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… |