Boa Vulnerabilities
132 vulnerabilities related to Boa
- PoC2026-08-16CVE-2026-15733: WGDashboard <= 4.3.2 - Authenticated OS Command Injection /etc/passwd Read
- PoC2026-08-16CVE-2026-53519: Nezha Dashboard < 2.0.13 - Path Traversal
- 2026-07-20Kubernetes Dashboard /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs 权限绕过漏洞(CVE-2018-18264)
- 2026-06-18Nezha Dashboard /dashboard../data/config.yaml 目录遍历漏洞(CVE-2026-53519)
- 2026-05-29Kubeflow Dashboard /api/workgroup/env-info 未授权访问漏洞
- PoC2026-05-09apache-skywalking-dashboard: Apache SkyWalking - Dashboard
- PoC2026-04-09CVE-2025-54597: Heimdall Application Dashboard < 2.7.3 - Reflected XSS
- PoC2026-04-09heimdall-dashboard-exposure: Heimdall Application Dashboard - Unauthenticated Access
- 2026-03-17泛微 E-cology10 dubboApi 代码执行漏洞
- PoC2026-01-24adminbro-dashboard-exposure: AdminBro Dashboard - Unauthenticated Access
- PoC2026-01-24administrate-dashboard: Administrate Dashboard Exposure
- PoC2026-01-24kanboard-database-exposure: Kanboard - SQLite Database Exposure
- PoC2026-01-24opennms-dashboard-exposure: OpenNMS Dashboard - Exposure Detection
- PoC2026-01-16CVE-2016-15041: MainWP Dashboard <= 3.1.2 - Stored Cross-Site Scripting
- PoC2026-01-16exist-db-dashboard-access: eXist-DB Dashboard Access
- PoC2026-01-16icinga-dashboard-exposure: Icinga Exposed Dashboard
- PoC2026-01-16lightstreamer-dashboard-exposure: Lightstreamer Dashboard Exposure
- PoC2025-12-12unauth-munin: Munin Monitoring Dashboard - Exposure
- PoC2025-12-02unauth-akhq-dashboard: AKHQ Dashboard - Unauthenticated Access
- PoC2025-12-02unauth-hawkeye-dashboard: Unauth Hawkeye Dashboard - Detect
- PoC2025-12-02unauth-phoenix-dashboard: Unauth Phoenix Dashboard - Detect
- PoC2025-12-02unauth-supervisor-dashboard: Unauth Supervisor Dashboard - Detect
- 2025-11-21Kuboard /api/login 默认口令漏洞
- 2025-11-21Kuboard /api/login 默认口令漏洞
- PoC2025-11-18CVE-2024-37656: GnuBoard5 5.5.16 - Open Redirect
- 2025-09-09MCPHub Dashboard JWT硬编码身份认证绕过漏洞
- 2025-08-25OpenSearch Dashboard为存在默认口令
- 2025-08-25OpenSearch Dashboard存在未授权访问
- 2025-08-09(CVE-2025-8757)TRENDnet TV-IP110WN 1.2.2 Embedded Boa Web Server权限违规漏洞
- PoC2025-08-01CVE-2004-1965: Open Bulletin Board (OpenBB) v1.0.6 - Open Redirect/XSS
- PoC2025-08-01CVE-2010-1658: Joomla! Component NoticeBoard 1.3 - Local File Inclusion
- PoC2025-08-01CVE-2010-2307: Motorola SBV6120E SURFboard Digital Voice Modem SBV6X2X-1.0.0.5-SCM - Directory Traversal
- PoC2025-08-01CVE-2017-9833: BOA Web Server 0.94.14 - Arbitrary File Access
- PoC2025-08-01CVE-2018-18264: Kubernetes Dashboard <1.10.1 - Authentication Bypass
- PoC2025-08-01CVE-2020-35749: WordPress Simple Job Board <2.9.4 - Local File Inclusion
- PoC2025-08-01CVE-2021-22053: Spring Cloud Netflix Hystrix Dashboard <2.2.10 - Remote Code Execution
- PoC2025-08-01CVE-2021-3223: Node RED Dashboard <2.26.2 - Local File Inclusion
- PoC2025-08-01CVE-2021-33558: Boa 0.94.13 - Information Disclosure
- PoC2025-08-01CVE-2022-1883: Terraboard <2.2.0 - SQL Injection
- PoC2025-08-01CVE-2022-2544: WordPress Ninja Job Board < 1.3.3 - Direct Request
- PoC2025-08-01CVE-2022-38817: Dapr Dashboard 0.1.0-0.10.0 - Improper Access Control
- PoC2025-08-01CVE-2023-0777: modoboa 2.0.4 - Admin TakeOver
- PoC2025-08-01CVE-2023-2227: Modoboa < 2.1.0 - Improper Authorization
- PoC2025-08-01CVE-2023-7246: System Dashboard < 2.8.10 - Cross-Site Scripting
- PoC2025-08-01CVE-2024-12824: Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
- PoC2025-08-01CVE-2025-47423: Personal Weather Station Dashboard 12 - Directory Traversal
- PoC2025-08-01CVE-2021-3223: Node RED Dashboard - Directory Traversal
- PoC2025-08-01kubernetes-dashboard-enabled: Kubernetes Dashboard for ACK Clusters - Enabled
- PoC2025-08-01CVE-2022-38817: Dapr Dashboard configurations 未授权访问漏洞
- PoC2025-08-01tensorboard-unauth: Tensorboard Unauth
- PoC2025-08-01jenkins-dashboard-unauth: Jenkins Dashboard 未授权访问
- PoC2025-08-01CVE-2021-3831: Gnuboard 5 - Cross-Site Scripting
- PoC2025-08-01CVE-2024-0593: WordPress Simple Job Board - Unauthorized Data Access
- PoC2025-08-01CVE-2024-10708: System Dashboard < 2.8.15 - Admin+ Path Traversal
- PoC2025-08-01kanboard-default-login: Kanboard - Default Login
- PoC2025-08-01opensearch-dashboard-default-login: OpenSearch Dashboard - Default Login
- PoC2025-08-01beego-admin-dashboard: Beego Admin Dashboard Panel- Detect
- PoC2025-08-01goodjob-dashboard: goodjob-dashboard
- PoC2025-08-01sidekiq-dashboard: Sidekiq Dashboard Panel - Detect
- PoC2025-08-01wiren-board-webui: Wiren Board WebUI Panel - Detect
- PoC2025-08-01tugboat-config-exposure: Tugboat Configuration File Exposure
- PoC2025-08-01ace-admin-dashboard: Ace Admin Dashboard - Detect
- PoC2025-08-01anteon-dashboard-unauth: Anteon Dashboard - Unauthenticated
- PoC2025-08-01atlantis-dashboard: Atlantis Dashboard - Exposure
- PoC2025-08-01clockwork-dashboard-exposure: Clockwork Dashboard Exposure
- PoC2025-08-01codis-dashboard: Codis Dashboard Exposure
- PoC2025-08-01confluence-dashboard: Confluence Dashboard Exposed
- PoC2025-08-01doris-dashboard: Doris Dashboard - Exposed
- PoC2025-08-01elastic-hd-dashboard: Elastic HD Dashboard Exposure
- PoC2025-08-01esphome-dashboard: ESPHome Dashboard Exposure
- PoC2025-08-01filebrowser-unauth: File Browser Dashboard - Unauthenticated Access
- PoC2025-08-01ganglia-cluster-dashboard: Ganglia Cluster Dashboard - Detect
- PoC2025-08-01h2o-dashboard: H2O Dashboard - Exposure
- PoC2025-08-01helm-dashboard-exposure: Helm Dashboard - Exposure
- PoC2025-08-01lidarr-dashboard-unauth: Lidarr Dashboard - Unauthenticated
- PoC2025-08-01mobiproxy-dashboard: MobiProxy Dashboard - Detect
- PoC2025-08-01netalertx-dashboard: NetAlert X Admin Dashboard - Exposed
- PoC2025-08-01nextcloudpi-dashboard: NextcloudPi Dashboard - Exposed
- PoC2025-08-01ntopng-traffic-dashboard: Ntopng Traffic Dashboard - Detect
- PoC2025-08-01opensearch-dashboard-unauth: OpenSearch Dashboard - Unauth Access
- PoC2025-08-01radarr-dashboard-unauth: Radarr Dashboard - Unauthenticated
- PoC2025-08-01ray-dashboard: Ray Dashboard Exposure
- PoC2025-08-01repetier-unauth: Repetier Server Dashboard - Unauthenticated
- PoC2025-08-01seq-dashboard-unauth: Seq Dashboard - Unauthenticated
- PoC2025-08-01simatic-dashboard-exposed: Siemens SIMATIC 300 Dashboard - Exposed
- PoC2025-08-01slurm-hpc-dashboard: Slurm HPC Dashboard - Detect
- PoC2025-08-01syncthing-dashboard: Syncthing Dashboard Exposure
- PoC2025-08-01transmission-dashboard: Transmission Dashboard - Detect
- PoC2025-08-01unauth-fastvue-dashboard: Fastvue Dashboard Panel - Unauthenticated Detect
- PoC2025-08-01unauthenticated-nginx-dashboard: Nginx Dashboard
- PoC2025-08-01unauthenticated-tensorboard: Tensorflow Tensorboard - Unauthenticated Access
- PoC2025-08-01whisparr-dashboard-unauth: Whisparr Dashboard - Unauthenticated
- PoC2025-08-01zabbix-dashboards-access: zabbix-dashboards-access
- PoC2025-08-01gnuboard-sms-xss: Gnuboard CMS - Cross-Site Scripting
- PoC2025-08-01gnuboard5-xss: Gnuboard 5 - Cross-Site Scripting
- PoC2025-08-01kedacom-network-lfi: Kedacom Network Keyboard Console - Arbitrary File Read
- PoC2025-08-01parentlink-xss: Blackboard - Cross-Site Scripting
- PoC2025-08-01squirrelmail-vkeyboard-xss: SquirrelMail Virtual Keyboard <=0.9.1 - Cross-Site Scripting
- PoC2025-08-01acrolinx-dashboard: Acrolinx Dashboard
- PoC2025-08-01openstack-dashboard-login: OpenStack Dashboard Login Panel - Detect
- 2025-07-07PWS Dashboard 存在任意文件读取漏洞(CVE-2025-47423)
- 2025-06-06Modoboa /api/v2/parameters/core/ 未授权访问漏洞 (CVE-2023-2227)
- 2025-06-06Modoboa /api/v2/parameters/core/ 未授权访问漏洞 (CVE-2023-2227)
- 2025-06-021000 Projects Online Notice Board 注入漏洞
- 2025-04-27(CVE-2025-3969) codeprojects News Publishing Site Dashboard Edit Category Page组件category_image参数不受限文件上传漏洞
- 2025-01-27WordPress plugin NOTICE BOARD BY TOWKIR 跨站脚本漏洞
- 2025-01-27WordPress plugin Job Board Manager 跨站请求伪造漏洞
- 2024-11-08Cisco Nexus Dashboard Fabric Controller SQL注入漏洞
- 2024-10-08Kuboard 弱口令漏洞
- 2024-10-02Cisco Nexus Dashboard Fabric 控制器和 Nexus Dashboard Orchestrator 信息泄露漏洞 (CVE-2024-20490)
- 2024-05-31Kubernetes Dashboard 认证绕过信息泄露漏洞
- 2024-04-26Modoboa core 存在未授权访问漏洞(CVE-2023-2227)
- PoC2024-02-28Kuboard默认口令
- 2024-02-22Camptocamp Terraboard CVE-2022-1883 SQL注入漏洞
- 2024-02-07Schneider Electric IGSS DashBoard.exe CVE-2023-3001 不安全反序列化漏洞
- 2023-12-29Gnuboard CMS XSS漏洞
- 2023-08-13Kuboard Spray默认口令
- 2023-07-30Terraboard <2.2.0 sql注入(CVE-2022-1883)
- 2023-05-19Wordpress wpjobboard 插件 wpjobboard 页面目录遍历漏洞(CVE-2022-2544)
- 2023-05-19Wordpress wpjobboard 插件 wpjobboard 页面目录遍历漏洞(CVE-2022-2544)
- 2023-05-11V2Board admin.php 越权访问漏洞
- 2023-05-11V2Board admin.php 越权访问漏洞
- 2023-04-18modoboa 安全漏洞
- 2023-01-29BOA Webserver 文件读取(CVE-2017-9833)
- 2022-10-26DaprDashboard未授权访问漏洞(CVE-2022-38817)
- 2022-03-01Boa/0.94.13信息泄露(CVE-2021-33558)
- 2021-01-19Parse Dashboard-未授权访问
- 2021-01-19IP.Board页面-SQL注入
- 2015-04-06C-BOARD Moyuku 任意文件上传漏洞
- 2009-09-03EkinBoard 任意文件上传漏洞
- 2009-08-24AlilG Application AliBoard 'usercp.php'任意文件上传漏洞
- 2009-05-28Jan_De_Graaff SimpleBoard 'image_upload.php'任意文件上传漏洞