Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

539 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.83%—Bijiadao Waimai Super CMS7/2/201917/6/2026
An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter.
ModificadaAlta (7.3)1.5%—Omron Cx-supervisor28/1/201917/6/2026
An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.
ModificadaAlta (7.3)1.5%—Omron Cx-supervisor22/1/201917/6/2026
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
ModificadaAlta (8.8)2.4%—Omron Cx-supervisor22/1/201917/6/2026
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the…
ModificadaMedia (5)0.75%—Omron Cx-supervisor22/1/201917/6/2026
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.
ModificadaAlta (8.8)2.4%—Omron Cx-supervisor22/1/201917/6/2026
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
ModificadaCrítica (9.8)1.1%—Bijiadao Waimai Super CMS2/1/201917/6/2026
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
ModificadaCrítica (9.8)53%💥 ExploitApache Superset7/11/201817/6/2026
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.
ModificadaAlta (7.8)1.6%—Omron Cx-supervisor5/11/201817/6/2026
A type confusion vulnerability exists when processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, which may allow an attacker to execute code in the context of the application.
ModificadaAlta (7.8)1.6%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior, the application fails to check if it is referencing freed memory, which may allow an attacker to execute code under the context of the application.
ModificadaBaja (3.3)0.89%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with the value of an offset, an attacker can force the application to read a value outside of an array.
ModificadaAlta (7.8)1.1%—Omron Cx-supervisor5/11/201817/6/2026
When processing project files in Omron CX-Supervisor Versions 3.4.1.0 and prior and tampering with a specific byte, memory corruption may occur within a specific object.
ModificadaMedia (6.1)0.68%—Bijiadao Waimai Super CMS23/10/201817/6/2026
An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username parameter.
ModificadaMedia (6.1)0.68%—Bijiadao Waimai Super CMS9/10/201817/6/2026
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI.
ModificadaMedia (6.5)1.1%—Cisco Unified Computing System DirectorCisco Integrated Management Controller Supervisor5/10/201817/6/2026
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Supervisor and Cisco UCS Director could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to insufficient restrictions on the size or total amount of…
ModificadaCrítica (9.8)3.2%💥 ExploitSuper CMS Blog PRO Project Super CMS Blog PRO28/9/201817/6/2026
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
ModificadaMedia (4.4)0.34%—Avaya Call Management System Supervisor24/9/201817/6/2026
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
ModificadaCrítica (9.8)56%💥 ExploitLG Supersign CMS21/9/201817/6/2026
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
ModificadaAlta (7.5)22%💥 PoCLG Supersign CMS14/9/201817/6/2026
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
ModificadaAlta (8.6)36%💥 ExploitLG Supersign CMS14/9/201817/6/2026
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
ModificadaCrítica (9.8)20%—LG Supersign CMS14/9/201817/6/2026
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
ModificadaCrítica (9.8)22%—LG Supersign CMS14/9/201817/6/2026
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
ModificadaMedia (6.5)0.45%—Bijiadao Waimai Super CMS1/9/201817/6/2026
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
ModificadaMedia (5.3)0.73%—Bijiadao Waimai Super CMS30/8/201817/6/2026
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=save item_totals parameter to zero, the entire cart is sold for free.
ModificadaMedia (4.8)0.52%—Bijiadao Waimai Super CMS20/8/201817/6/2026
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
Orbitaley — Vulnerabilidades