Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.54% | — | Opensearch DashboardsAI | 8/9/2026 | 9/9/2026 | Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty… | |
| Pendiente de análisis | Media (6.2) | 0.52% | — | Opensearch Dashboards-observabilityAI | 21/8/2026 | 27/8/2026 | Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web… | |
| Pendiente de análisis | Alta (8.7) | 0.66% | — | Opensearch DashboardsAI | 20/8/2026 | 25/8/2026 | Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code… | |
| Pendiente de análisis | Alta (8.7) | 0.72% | — | Opensearch DashboardsAI | 18/8/2026 | 20/8/2026 | Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request. | |
| Aplazada | Media (6.4) | 0.60% | — | Opensearch Dashboards-reportingAIOpensearchAI | 12/2/2025 | 17/6/2026 | dashboards-reporting (aka Dashboards Reports) before 2.19.0.0, as shipped in OpenSearch before 2.19, allows XSS because Markdown is not sanitized when previewing a header or footer. | |
| Analizada | Alta (8.8) | 0.44% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 24/1/2025 | 17/6/2026 | IBM Cognos Dashboards 4.0.7 and 5.0.0 on Cloud Pak for Data could allow a remote attacker to perform unauthorized actions due to dependency confusion. | |
| Aplazada | Media (6.1) | 0.26% | — | Opensearch DashboardsAIOpensearch SecurityAI | 23/8/2024 | 17/6/2026 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available in 1.3.19 and… | |
| Modificada | Crítica (9.8) | 2.0% | — | Stimulsoft Dashboards.php | 6/2/2024 | 9/7/2026 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function. | |
| Modificada | Media (5.4) | 0.76% | — | Stimulsoft Dashboards.js | 5/2/2024 | 9/7/2026 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field. | |
| Modificada | Media (6.5) | 0.52% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a victim to a phishing site. IBM X-Force ID: 262482. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in environment variables which could aid in further attacks against the system. IBM X-Force ID: 260736. | |
| Modificada | Alta (7.5) | 0.36% | — | IBM Cognos Dashboards ON Cloud PAK FOR Data | 22/10/2023 | 17/6/2026 | IBM Cognos Dashboards on Cloud Pak for Data 4.7.0 exposes sensitive information in container images which could lead to further attacks against the system. IBM X-Force ID: 260730. | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level. | |
| Modificada | Media (5.4) | 0.63% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an… | |
| Modificada | Alta (7.2) | 2.1% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+1 | 1/12/2020 | 17/6/2026 | A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage. | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | |
| Modificada | Alta (8.1) | 0.74% | — | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. The SSO implementation is affected by a weak obfuscation library, allowing man-in-the-middle attackers to discover credentials. | |
| Modificada | Alta (7.5) | 1.5% | — | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idb/config?CMD=installLicense URI, as demonstrated by intranet IP addresses and names of guest accounts. | |
| Modificada | Alta (7.5) | 1.5% | — | Idashboards | 18/2/2018 | 17/6/2026 | An issue was discovered in iDashboards 9.6b. It allows remote attackers to obtain sensitive information via a direct request for the idashboards/config.xml URI, as demonstrated by intranet URLs for reports. |