Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
539 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.2% | — | Apache Superset | 16/1/2023 | 17/6/2026 | A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag… | |
| Modificada | Alta (7.8) | 0.27% | — | HPE Superdome Flex 280 FirmwareHPE Superdome Flex Firmware | 5/1/2023 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome Flex firmware 3.60.50 and below and… | |
| Modificada | Media (5.4) | 0.48% | — | Apusthemes Superio | 2/1/2023 | 17/6/2026 | The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 23% | — | Nintendo Animal Crossing\Nintendo ArmsNintendo Mario Kart 7Nintendo Mario Kart 8+5 | 24/12/2022 | 17/6/2026 | The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remote attackers to execute arbitrary code via a large UDP packet that causes a buffer overflow, aka ENLBufferPwn. The victim must join a game session with the attacker. Other affected products include… | |
| Modificada | Alta (7.5) | 0.71% | — | Superwhite Demon Image Annotation | 13/12/2022 | 17/6/2026 | The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and including 5.0. This is due to the plugin improperly validating the number of characters supplied during an annotation despite there being a setting to limit the number characters input. This means that… | |
| Modificada | Alta (7.8) | 0.44% | — | Super Xray Project Super Xray | 25/11/2022 | 17/6/2026 | super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit `4d0d5966` and will be included in future… | |
| Modificada | Alta (7.8) | 0.40% | — | Super Xray Project Super Xray | 22/11/2022 | 17/6/2026 | super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta. | |
| Modificada | Crítica (9.8) | 0.84% | — | Super-xray Project Super-xray | 21/11/2022 | 17/6/2026 | super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta. | |
| Analizada | Media (4.8) | 0.53% | — | Themepoints Super Testimonials | 14/11/2022 | 17/6/2026 | The Testimonials WordPress plugin before 2.7, super-testimonial-pro WordPress plugin before 1.0.8 do not sanitize and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8.8) | 0.52% | — | Superwhite Demon Image Annotation | 28/10/2022 | 17/6/2026 | The demon image annotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.7. This is due to missing nonce validation in the ~/includes/settings.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web… | |
| Analizada | Media (4.8) | 0.46% | — | Themepoints Super Testimonials | 28/10/2022 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Themepoints Testimonials plugin <= 2.6 on WordPress. | |
| Modificada | Alta (8.8) | 0.40% | — | Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+140 | 25/8/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Nexus 3016 FirmwareCisco Nexus 3016q FirmwareCisco Nexus 3048 FirmwareCisco Nexus 3064 Firmware+143 | 25/8/2022 | 17/6/2026 | A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 0.49% | — | Supersmart.me - Walk Through | 5/8/2022 | 17/6/2026 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code. | |
| Modificada | Media (5.5) | 0.18% | — | Supersmart.me - Walk Through | 21/7/2022 | 17/6/2026 | It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX | |
| Modificada | Media (4.3) | 1.4% | — | Apache Superset | 6/7/2022 | 17/6/2026 | Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics. | |
| Modificada | Crítica (9.8) | 1.5% | — | HPE Slingshot FirmwareHPE Cray EX Supercomputers FirmwareHPE Cray SH Supercomputer AIR Cooled Base System Code FirmwareHPE Cray SH Supercomputer Liquid Cooled Base System Code Firmware+1 | 24/6/2022 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis controller firmware associated with HPE Cray EX… | |
| Modificada | Crítica (9.8) | 1.6% | — | Marketingheroes Sitesupercharger | 2/5/2022 | 17/6/2026 | The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections | |
| Modificada | Crítica (9.8) | 2.9% | — | Apache Superset | 13/4/2022 | 17/6/2026 | Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | |
| Modificada | Media (6.7) | 0.24% | — | HPE Superdome Flex Server FirmwareHPE Superdome Flex 280 Server Firmware | 12/4/2022 | 17/6/2026 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnerability could be locally exploited to allow an user with Administrator access to escalate their privilege. The vulnerability is resolved in the latest firmware update. HPE Superdome Flex Server… | |
| Modificada | Media (6.1) | 1.9% | 💥 Exploit | Heateor Super Socializer | 11/4/2022 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in the response, leading to a Reflected Cross-Site… | |
| Modificada | Media (4.3) | 1.1% | — | OSU Ohio Supercomputer Center Open Ondemand | 26/2/2022 | 17/6/2026 | The Job Composer app in Ohio Supercomputer Center Open OnDemand before 1.7.19 and 1.8.x before 1.8.18 allows remote authenticated users to provide crafted input in a job template. | |
| Modificada | Crítica (9.8) | 2.3% | — | Blitzjs BlitzBlitzjs Superjson | 9/2/2022 | 17/6/2026 | superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the server implements at least one endpoint… | |
| Modificada | Media (6.5) | 7.9% | 💥 Exploit | Apache Superset | 1/2/2022 | 17/6/2026 | Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher. | |
| Modificada | Alta (7.8) | 0.32% | — | Superantispyware | 28/12/2021 | 17/6/2026 | SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140. |