Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

537 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.48%—Superwebmailer20/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
ModificadaMedia (5.4)0.45%—Themepoints Super Testimonials20/10/202317/6/2026
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpsscode' shortcode in all versions up to, and including, 2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaCrítica (9.8)0.58%—Knowband Supercheckout19/10/202317/6/2026
KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php
ModificadaAlta (8.8)0.25%—Dipakgajjar WP Super Minify6/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions.
ModificadaAlta (8.8)1.7%—Superstorefinder Super Store Finder2/10/202317/6/2026
Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.
ModificadaMedia (5.3)1.7%—Canonical Ubuntu LinuxAMD Ryzen 7 4800uIntel Core I7-10510uIntel Core I7-12700k+1227/9/202317/6/2026
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text…
ModificadaAlta (7.2)1.0%—Superstorefinder Super Store Finder27/9/202317/6/2026
Super Store Finder v3.6 and below was discovered to contain a SQL injection vulnerability via the Search parameter at /admin/stores.php.
ModificadaMedia (5.3)0.64%—Superstorefinder Super Store Finder19/9/202317/6/2026
The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versions up to, and including, 6.9.3. This is due to insufficient restrictions on the sendMail.php file that allows direct access. This makes it possible for unauthenticated attackers to send emails…
ModificadaCrítica (9.8)1.7%—Superstorefinder PHP Script14/9/202317/6/2026
SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.
ModificadaMedia (6.5)86%💥 ExploitApache Superset6/9/202317/6/2026
Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database…
ModificadaMedia (6.6)35%💥 ExploitApache Superset6/9/202317/6/2026
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system…
ModificadaMedia (4.3)1.0%—Apache Superset6/9/202317/6/2026
An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leveraging a SQL parsing vulnerability.
ModificadaMedia (4.3)1.1%—Apache Superset6/9/202317/6/2026
By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset versions up to and including 2.1.0.
ModificadaMedia (5.4)1.1%—Apache Superset6/9/202317/6/2026
Improper REST API permission in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma users to test network connections, possible SSRF.
ModificadaMedia (5.4)1.1%—Apache Superset6/9/202317/6/2026
An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
ModificadaMedia (4.3)1.2%—Apache Superset6/9/202317/6/2026
A non Admin authenticated user could incorrectly create resources using the import charts feature, on Apache Superset up to and including 2.1.0.
ModificadaMedia (4.3)1.0%—Apache Superset6/9/202317/6/2026
Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to.
ModificadaCrítica (9.8)0.99%💥 PoCSuperstorefinder Super Store Finder5/9/202317/6/2026
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
ModificadaCrítica (9.8)1.4%💥 PoCSuperstorefinder Super Store Finder5/9/202317/6/2026
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
ModificadaMedia (4.8)0.35%—Supersoju Block Referer Spam23/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 versions.
ModificadaAlta (7.8)0.39%💥 PoCSupermicro X12dai-n6 FirmwareSupermicro X12ddw-a6 FirmwareSupermicro X12dgo-6 FirmwareSupermicro X12dgq-r Firmware+26722/8/202317/6/2026
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
ModificadaAlta (7.2)0.92%—Supermicro-cms Project Supermicro-cms11/8/202317/6/2026
An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.
ModificadaMedia (4.9)0.55%—Supermicro-cms Project Supermicro-cms11/8/202317/6/2026
An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.
ModificadaCrítica (9.8)2.1%—Supermicro H12dst-b FirmwareSupermicro X13dai-t FirmwareSupermicro X13ddw-a FirmwareSupermicro X13deg-oa Firmware+16131/7/202317/6/2026
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
ModificadaMedia (5.4)0.58%—Activeitzone Active Super Shop20/7/202317/6/2026
A vulnerability, which was classified as problematic, has been found in ActiveITzone Active Super Shop CMS 2.5. This issue affects some unknown processing of the component Manage Details Page. The manipulation of the argument name/phone/address leads to cross site scripting. The attack may be initiated remotely. The…
Orbitaley — Vulnerabilidades