Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.28% | — | Supsystic MembershipAI | 16/5/2026 | 29/9/2026 | Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payloads to extract sensitive database… | |
| Aplazada | Alta (8.8) | 0.28% | — | Supsystic Pricing TableAI | 16/5/2026 | 29/9/2026 | Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit name' and 'Edit HTML' fields that… | |
| Aplazada | Alta (8.8) | 0.28% | — | Supsystic Ultimate MapsAI | 16/5/2026 | 29/9/2026 | Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL… | |
| Aplazada | Crítica (9.8) | 33% | 💥 Exploit | Supsystic Contact FormAI | 30/3/2026 | 17/6/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill`… | |
| Pendiente de análisis | Crítica (9.3) | 0.48% | — | Synopsys Coverity ConnectAI | 27/3/2026 | 17/6/2026 | Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a specially crafted HTTP… | |
| Analizada | Alta (7.3) | 0.33% | — | Psysh | 30/1/2026 | 17/6/2026 | PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when… | |
| Modificada | Crítica (9.3) | 0.65% | — | Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem | 30/12/2025 | 24/9/2026 | Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | |
| Aplazada | Media (6.5) | 0.62% | — | Supsystic Data Tables GeneratorAI | 13/11/2025 | 17/6/2026 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cleanCache() function in all versions up to, and including, 1.10.45. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Contact Form BY SupsysticAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Reflected XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.36. | |
| Aplazada | Media (6.1) | 0.31% | — | Supsystic Contact FormAI | 16/4/2025 | 17/6/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.29. This is due to missing or incorrect nonce validation on a saveAsCopy function. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (6.6) | 0.53% | — | Supsystic Easy Google MapsAI | 4/4/2025 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18. | |
| Aplazada | Media (5.4) | 0.32% | — | Data-tables-generator-by-supsysticAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in supsystic Data Tables Generator by Supsystic data-tables-generator-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Data Tables Generator by Supsystic: from n/a through <= 1.10.36. | |
| Aplazada | Alta (8) | 0.24% | — | BD Diagnostic SolutionsAIBD Synapsys Informatics SolutionAIBD Kiestra SCUAI | 17/12/2024 | 17/6/2026 | Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may… | |
| Modificada | Crítica (9.8) | 0.67% | — | Supsystic Popup | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through 1.10.19. | |
| Modificada | Crítica (9.8) | 0.57% | — | Supsystic Popup | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19. | |
| Modificada | Crítica (9.1) | 1.1% | — | Supsystic Popup | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29. | |
| Aplazada | Media (5.9) | 0.27% | — | Contact Form BY SupsysticAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Stored XSS.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28. | |
| Aplazada | Crítica (9.1) | 1.1% | — | Contact Form BY SupsysticAI | 16/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28. | |
| Analizada | Alta (8.8) | 0.35% | — | Supsystic SliderSupsystic Social Share Buttons | 26/9/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons by Supsystic: from n/a through 2.2.9. | |
| Modificada | Media (5.4) | 0.34% | — | Supsystic Easy Google Maps | 2/7/2024 | 17/6/2026 | The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Aplazada | Media (4.3) | 0.35% | — | Supsystic Pricing TableAI | 17/5/2024 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12. | |
| Modificada | Media (6.5) | 1.3% | 💥 PoC | Supsystic Popup | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19. | |
| Aplazada | Media (5.3) | 0.42% | — | Supsystic Digital PublicationsAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publications by Supsystic: from n/a through 1.7.7. | |
| Aplazada | Media (4.3) | 0.37% | — | Supsystic Data Tables GeneratorAI | 26/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Supsystic Data Tables Generator by Supsystic.This issue affects Data Tables Generator by Supsystic: from n/a through 1.10.31. | |
| Aplazada | Media (4.3) | 0.52% | — | Supsystic Data Tables GeneratorAI | 17/4/2024 | 17/6/2026 | Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data Tables Generator: from n/a through 1.10.25. |