Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

539 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)1.2%—Apache Superset16/1/202317/6/2026
A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag…
ModificadaAlta (7.8)0.27%—HPE Superdome Flex 280 FirmwareHPE Superdome Flex Firmware5/1/202317/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome Flex firmware 3.60.50 and below and…
ModificadaMedia (5.4)0.48%—Apusthemes Superio2/1/202317/6/2026
The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks.
ModificadaCrítica (9.8)23%—Nintendo Animal Crossing\Nintendo ArmsNintendo Mario Kart 7Nintendo Mario Kart 8+524/12/202217/6/2026
The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include…
ModificadaAlta (7.5)0.71%—Superwhite Demon Image Annotation13/12/202217/6/2026
The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and including 5.0. This is due to the plugin improperly validating the number of characters supplied during an annotation despite there being a setting to limit the number characters input. This means that…
ModificadaAlta (7.8)0.44%—Super Xray Project Super Xray25/11/202217/6/2026
super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit `4d0d5966` and will be included in future…
ModificadaAlta (7.8)0.40%—Super Xray Project Super Xray22/11/202217/6/2026
super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.
ModificadaCrítica (9.8)0.84%—Super-xray Project Super-xray21/11/202217/6/2026
super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.
AnalizadaMedia (4.8)0.53%—Themepoints Super Testimonials14/11/202217/6/2026
The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaAlta (8.8)0.52%—Superwhite Demon Image Annotation28/10/202217/6/2026
The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7. This is due to missing nonce validation in the ~/includes/settings.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web…
AnalizadaMedia (4.8)0.46%—Themepoints Super Testimonials28/10/202217/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress.
ModificadaAlta (8.8)0.40%—Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+14025/8/202217/6/2026
A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input…
ModificadaAlta (8.6)1.1%—Cisco Nexus 3016 FirmwareCisco Nexus 3016q FirmwareCisco Nexus 3048 FirmwareCisco Nexus 3064 Firmware+14325/8/202217/6/2026
A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this…
ModificadaAlta (7.5)0.49%—Supersmart.me - Walk Through5/8/202217/6/2026
insert HTML / js code inside input how to get to the vulnerable input : Workers &gt; worker nickname &gt; inject in this input the code.
ModificadaMedia (5.5)0.18%—Supersmart.me - Walk Through21/7/202217/6/2026
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
ModificadaMedia (4.3)1.4%—Apache Superset6/7/202217/6/2026
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics.
ModificadaCrítica (9.8)1.5%—HPE Slingshot FirmwareHPE Cray EX Supercomputers FirmwareHPE Cray SH Supercomputer AIR Cooled Base System Code FirmwareHPE Cray SH Supercomputer Liquid Cooled Base System Code Firmware+124/6/202217/6/2026
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX…
ModificadaCrítica (9.8)1.6%—Marketingheroes Sitesupercharger2/5/202217/6/2026
The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections
ModificadaCrítica (9.8)2.9%—Apache Superset13/4/202217/6/2026
Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue.
ModificadaMedia (6.7)0.24%—HPE Superdome Flex Server FirmwareHPE Superdome Flex 280 Server Firmware12/4/202217/6/2026
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally exploited to allow an user with Administrator access to escalate their privilege. The vulnerability is resolved in the latest firmware update. HPE Superdome Flex Server…
ModificadaMedia (6.1)1.9%💥 ExploitHeateor Super Socializer11/4/202217/6/2026
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site…
ModificadaMedia (4.3)1.1%—OSU Ohio Supercomputer Center Open Ondemand26/2/202217/6/2026
The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template.
ModificadaCrítica (9.8)2.3%—Blitzjs BlitzBlitzjs Superjson9/2/202217/6/2026
superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the server implements at least one endpoint…
ModificadaMedia (6.5)7.9%💥 ExploitApache Superset1/2/202217/6/2026
Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.
ModificadaAlta (7.8)0.32%—Superantispyware28/12/202117/6/2026
SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.