Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
537 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.6) | 0.15% | — | Multi Emulator Super SystemAI | 28/3/2026 | 17/6/2026 | Multi Emulator Super System 0.154-3.1 contains a buffer overflow vulnerability in the gamma parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized gamma parameter value to overflow the stack buffer and overwrite the instruction pointer with… | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Home-assistant Home AssistantAIHome-assistant SupervisorAI | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict… | |
| Aplazada | Media (6.5) | 0.20% | — | Super Stage WPAI | 28/2/2026 | 17/6/2026 | The Super Stage WP WordPress plugin through 1.0.1 unserializes user input via REQUEST, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Analizada | Alta (7.1) | 0.36% | — | Apache Superset | 24/2/2026 | 17/6/2026 | An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively blocks standard Data Manipulation Language (DML) statements (e.g., INSERT,… | |
| Analizada | Baja (2.3) | 0.42% | — | Apache Superset | 24/2/2026 | 17/6/2026 | A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a specific tag. When these associated objects include Users, the API response… | |
| Analizada | Alta (7.1) | 0.45% | — | Apache Superset | 24/2/2026 | 17/6/2026 | An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized data. However, an authenticated attacker with permissions to write datasets and… | |
| Analizada | Media (5.3) | 0.65% | 💥 PoC | Apache Superset | 24/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affects Apache Superset: before 6.0.0. Users are recommended to… | |
| Analizada | Media (5.3) | 0.62% | — | Apache Superset | 24/2/2026 | 17/6/2026 | Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL, a vulnerability was reported where the default list for the ClickHouse engine… | |
| Aplazada | Alta (7.2) | 0.20% | — | Optimole Super Page CacheAI | 14/2/2026 | 17/6/2026 | The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.2) | 0.36% | — | Super Simple Contact FormAI | 14/2/2026 | 17/6/2026 | The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Analizada | Alta (8.8) | 2.4% | — | Super-linter Project Super-linter | 9/2/2026 | 17/6/2026 | Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull request that introduces… | |
| Modificada | Alta (7.8) | 0.11% | 💥 PoC | Shirt-pocket Superduper! | 29/1/2026 | 5/7/2026 | An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls. | |
| Aplazada | Alta (7.1) | 0.21% | — | Highwarden Super Logos ShowcaseAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Logos Showcase superlogoshowcase-wp allows Reflected XSS.This issue affects Super Logos Showcase: from n/a through <= 2.8. | |
| Aplazada | Alta (7.1) | 0.28% | — | Highwarden Super Interactive MapsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Interactive Maps super-interactive-maps allows Reflected XSS.This issue affects Super Interactive Maps: from n/a through <= 2.3. | |
| Aplazada | Alta (8.4) | 0.13% | — | Supermicro Mbd-x13sem-fAI | 16/1/2026 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Alta (7.2) | 0.31% | — | Supermicro Bmd-x12stw-fAI | 16/1/2026 | 17/6/2026 | There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW-F . An attacker can update the system firmware with a specially crafted image. | |
| Aplazada | Media (6.9) | 0.43% | — | Red-v Super Digital Signage SystemAI | 6/1/2026 | 17/6/2026 | RED-V Super Digital Signage System 5.1.1 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive webserver log files. Attackers can visit multiple endpoints to retrieve system resources and debug log information without authentication. | |
| Analizada | Alta (7.8) | 0.20% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.20% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.20% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.20% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.20% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.21% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.21% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.21% | — | Superantispyware | 23/12/2025 | 17/6/2026 | RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in… |