Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
539 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Bijiadao Waimai Super CMS | 7/2/2019 | 17/6/2026 | An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter. | |
| Modificada | Alta (7.3) | 1.5% | — | Omron Cx-supervisor | 28/1/2019 | 17/6/2026 | An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application. | |
| Modificada | Alta (7.3) | 1.5% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application. | |
| Modificada | Alta (8.8) | 2.4% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the… | |
| Modificada | Media (5) | 0.75% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. | |
| Modificada | Alta (8.8) | 2.4% | — | Omron Cx-supervisor | 22/1/2019 | 17/6/2026 | CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bijiadao Waimai Super CMS | 2/1/2019 | 17/6/2026 | An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI. | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Apache Superset | 7/11/2018 | 17/6/2026 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application. | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application. | |
| Modificada | Baja (3.3) | 0.89% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array. | |
| Modificada | Alta (7.8) | 1.1% | — | Omron Cx-supervisor | 5/11/2018 | 17/6/2026 | When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object. | |
| Modificada | Media (6.1) | 0.68% | — | Bijiadao Waimai Super CMS | 23/10/2018 | 17/6/2026 | An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Bijiadao Waimai Super CMS | 9/10/2018 | 17/6/2026 | XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor | 5/10/2018 | 17/6/2026 | A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of… | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Super CMS Blog PRO Project Super CMS Blog PRO | 28/9/2018 | 17/6/2026 | SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter. | |
| Modificada | Media (4.4) | 0.34% | — | Avaya Call Management System Supervisor | 24/9/2018 | 17/6/2026 | A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | LG Supersign CMS | 21/9/2018 | 17/6/2026 | LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail. | |
| Modificada | Alta (7.5) | 22% | 💥 PoC | LG Supersign CMS | 14/9/2018 | 17/6/2026 | LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080. | |
| Modificada | Alta (8.6) | 36% | 💥 Exploit | LG Supersign CMS | 14/9/2018 | 17/6/2026 | LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs. | |
| Modificada | Crítica (9.8) | 20% | — | LG Supersign CMS | 14/9/2018 | 17/6/2026 | LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs. | |
| Modificada | Crítica (9.8) | 22% | — | LG Supersign CMS | 14/9/2018 | 17/6/2026 | LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits. | |
| Modificada | Media (6.5) | 0.45% | — | Bijiadao Waimai Super CMS | 1/9/2018 | 17/6/2026 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add. | |
| Modificada | Media (5.3) | 0.73% | — | Bijiadao Waimai Super CMS | 30/8/2018 | 17/6/2026 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals parameter to zero, the entire cart is sold for free. | |
| Modificada | Media (4.8) | 0.52% | — | Bijiadao Waimai Super CMS | 20/8/2018 | 17/6/2026 | In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter. |