Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

537 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.31%—Skoda-auto Superb 3 Firmware12/1/202417/6/2026
The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III (3V3) - 2.0 TDI manufactured in 2022.
ModificadaAlta (8.8)1.2%—Apache Superset19/12/202317/6/2026
A where_in JINJA macro allows users to specify a quote, which combined with a carefully crafted statement would allow for SQL injection in Apache Superset.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are recommended to upgrade to version 3.0.2, which fixes the issue.
ModificadaMedia (6.5)0.95%—Apache Superset19/12/202317/6/2026
An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.2, from 3.0.0 before 3.0.2. Users are…
ModificadaMedia (6.5)1.7%—Apache Superset19/12/202317/6/2026
Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.
ModificadaMedia (5.5)0.22%—Supermailer13/12/202317/6/2026
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerability by sending a malicious configuration file (file with SMB extension) to a user via a link or email attachment and persuade the user to open the file with the affected…
ModificadaAlta (8.8)0.96%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
ModificadaAlta (8.8)1.2%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi…
ModificadaAlta (7.5)1.3%—Supermicro M11sdv-4c-ln4f FirmwareSupermicro M11sdv-4ct-ln4f FirmwareSupermicro M11sdv-8c-ln4f FirmwareSupermicro M11sdv-8ct-ln4f Firmware+3587/12/20239/7/2026
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
ModificadaAlta (8.8)0.26%—Superblogme Broken Link Checker FOR Youtube30/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3.
ModificadaMedia (6.5)1.1%—Apache Superset28/11/202317/6/2026
An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0
ModificadaMedia (4.3)1.0%—Apache Superset28/11/202317/6/2026
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.
ModificadaMedia (5.4)0.83%—Apache Superset28/11/202317/6/2026
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset versions before 3.0.0.
ModificadaMedia (5.4)1.0%—Apache Superset27/11/202317/6/2026
Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to…
ModificadaMedia (4.3)0.86%—Apache Superset27/11/202317/6/2026
Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to reconstruct the Gamma role or remove `can_read` permission…
ModificadaAlta (8.8)1.3%—Apache Superset27/11/202317/6/2026
Improper authorization check and possible privilege escalation on Apache Superset up to but excluding 2.1.2. Using the default examples database connection that allows access to both the examples schema and Apache Superset's metadata database, an attacker using a specially crafted CTE SQL statement could change data…
ModificadaAlta (7.5)0.37%—Superagi16/11/202317/6/2026
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This vulnerability can lead to the disclosure of information and communications.
ModificadaAlta (8.8)0.33%—Ifeelweb Affiliate Super Assistent12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Timo Reith Affiliate Super Assistent plugin <= 1.5.1 versions.
ModificadaAlta (8.8)0.31%—Superbthemes Superb Social Media Share Buttons AND Follow Buttons10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.
ModificadaAlta (7.2)0.68%—Superwhite Demon Image Annotation4/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Demonisblack demon image annotation allows SQL Injection.This issue affects demon image annotation: from n/a through 5.1.
ModificadaMedia (6.5)0.79%—Gopiplus Superb Slideshow Gallery31/10/202317/6/2026
The Superb slideshow gallery plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 13.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers…
ModificadaAlta (7.5)0.82%—Idnovate Superuser31/10/202317/6/2026
An issue in the component SuperUserSetuserModuleFrontController:init() of idnovate superuser before v2.4.2 allows attackers to bypass authentication via a crafted HTTP call.
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
ModificadaAlta (8.8)1.3%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
ModificadaAlta (8.8)0.66%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.