Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
539 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.3) | 0.28% | — | Pulsesecure Psa-5000 FirmwarePulsesecure Psa-7000 FirmwareSupermicro X10slh-f FirmwareSupermicro X10sll-f Firmware+8 | 16/3/2021 | 17/6/2026 | A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device. | |
| Modificada | Media (5.4) | 86% | — | Apache Superset | 5/3/2021 | 17/6/2026 | Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javascript code will be… | |
| Modificada | Alta (7.5) | 1.5% | — | Vm-superio Project Vm-superio | 16/10/2020 | 17/6/2026 | In vm-superio before 0.1.1, the serial console FIFO can grow to unlimited memory usage when data is sent to the input source (i.e., standard input). This behavior cannot be reproduced from the guest side. When no rate limiting is in place, the host can be subject to memory pressure, impacting all other VMs running on… | |
| Modificada | Alta (8.1) | 2.0% | — | Apache Superset | 30/9/2020 | 17/6/2026 | In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the hashed version of the authenticated users’… | |
| Modificada | Alta (8.8) | 3.1% | — | Apache Superset | 17/9/2020 | 17/6/2026 | While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions < 0.37.1. It was thus possible for an… | |
| Modificada | Alta (7.8) | 0.91% | 💥 PoC | Superantispyware Professional X | 1/9/2020 | 17/6/2026 | SUPERAntiSyware Professional X Trial 10.0.1206 is vulnerable to local privilege escalation because it allows unprivileged users to restore a malicious DLL from quarantine into the system32 folder via an NTFS directory junction, as demonstrated by a crafted ualapi.dll file that is detected as malware. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Superwebmailer | 14/7/2020 | 17/6/2026 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection. | |
| Modificada | Alta (8.8) | 2.3% | 💥 Exploit | Supermicro X10drh-it BiosSupermicro X10drh-it Firmware | 24/6/2020 | 17/6/2026 | The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to exploit a cgi/config_user.cgi CSRF issue to add new admin users. The fixed versions are BIOS 3.2 and firmware 03.88. | |
| Modificada | Media (6.7) | 0.30% | — | HPE Superdome Flex Server Firmware | 19/5/2020 | 17/6/2026 | A validation issue in HPE Superdome Flex's RMC component may allow local elevation of privilege. Apply HPE Superdome Flex Server version 3.25.46 or later to resolve this issue. | |
| Modificada | Media (4.3) | 0.68% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 6/5/2020 | 17/6/2026 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect… | |
| Modificada | Crítica (9.8) | 74% | 💥 Exploit | Automattic WP Super CacheBoldgrid W3 Total Cache | 12/2/2020 | 16/6/2026 | WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 13% | 💥 Exploit | Automattic WP Super Cache | 7/2/2020 | 16/6/2026 | WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution | |
| Modificada | Media (6.1) | 1.5% | — | Automattic WP Super Cache | 7/2/2020 | 16/6/2026 | WordPress Super Cache Plugin 1.3 has XSS. | |
| Modificada | Alta (8.8) | 1.5% | — | Super File Explorer Project Super File Explorer | 28/1/2020 | 17/6/2026 | An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service. | |
| Modificada | Media (6.5) | 1.4% | — | Apache Superset | 28/1/2020 | 17/6/2026 | An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset. | |
| Modificada | Media (4.3) | 4.4% | — | Supermicro Intelligent Platform Management Interface | 23/1/2020 | 17/6/2026 | Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter. | |
| Modificada | Media (5.5) | 0.76% | — | HPE Superdome Flex Server Firmware | 16/1/2020 | 17/6/2026 | HPE Superdome Flex Server is vulnerable to multiple remote vulnerabilities via improper input validation of administrator commands. This vulnerability could allow an Administrator to bypass security restrictions and access multiple remote vulnerabilities including information disclosure, or denial of service. HPE has… | |
| Modificada | Alta (7.5) | 3.6% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312. | |
| Modificada | Alta (8.1) | 9.7% | — | Supermicro SMT X9 FirmwareSupermicro SMT X8 FirmwareCitrix Netscaler SDX FirmwareCitrix Netscaler Firmware+1 | 2/1/2020 | 16/6/2026 | Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon. | |
| Modificada | Alta (8.8) | 5.1% | — | Automattic W3 Super Cache | 26/12/2019 | 16/6/2026 | WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009. | |
| Modificada | Media (5.3) | 2.8% | — | Apache Superset | 16/12/2019 | 17/6/2026 | In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab | |
| Modificada | Media (5.3) | 2.8% | — | Apache Superset | 16/12/2019 | 17/6/2026 | In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query. | |
| Modificada | Alta (8.8) | 19% | — | Supermicro X8sti-f BiosSupermicro X8sti-f Firmware | 8/12/2019 | 17/6/2026 | On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/setvmdrive.asp with shell metacharacters in ShareHost or ShareName. The attacker… | |
| Modificada | Alta (8.8) | 1.7% | — | Omron Cx-supervisorTeamviewer | 26/11/2019 | 17/6/2026 | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit. | |
| Modificada | Crítica (10) | 2.2% | — | Supermicro X11dai-n FirmwareSupermicro X11dac FirmwareSupermicro X11dph-tq FirmwareSupermicro X11dph-i Firmware+259 | 21/9/2019 | 17/6/2026 | On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the… |