Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.3% | — | Apache Superset | 16/1/2023 | 17/6/2026 | An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | |
| Modificada | Alta (8.8) | 0.57% | — | Apache Superset | 16/1/2023 | 17/6/2026 | Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | |
| Modificada | Media (5.4) | 1.1% | — | Apache Superset | 16/1/2023 | 17/6/2026 | Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | |
| Modificada | Media (5.4) | 1.3% | — | Apache Superset | 16/1/2023 | 17/6/2026 | Dashboard rendering does not sufficiently sanitize the content of markdown components leading to possible XSS attack vectors that can be performed by authenticated users with create dashboard permissions. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | |
| Modificada | Media (5.4) | 1.2% | — | Apache Superset | 16/1/2023 | 17/6/2026 | A vulnerability in the SQL Alchemy connector of Apache Superset allows an authenticated user with read access to a specific database to add subqueries to the WHERE and HAVING fields referencing tables on the same database that the user should not have access to, despite the user having the feature flag… | |
| Modificada | Media (4.3) | 1.4% | — | Apache Superset | 6/7/2022 | 17/6/2026 | Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics. | |
| Modificada | Crítica (9.8) | 2.9% | — | Apache Superset | 13/4/2022 | 17/6/2026 | Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. | |
| Modificada | Media (6.5) | 7.9% | 💥 Exploit | Apache Superset | 1/2/2022 | 17/6/2026 | Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher. | |
| Modificada | Media (6.5) | 1.8% | — | Apache Superset | 17/11/2021 | 17/6/2026 | Improper output neutralization for Logs. A specific Apache Superset HTTP endpoint allowed for an authenticated user to forge log entries or inject malicious content into logs. | |
| Modificada | Media (6.5) | 1.5% | — | Apache Superset | 12/11/2021 | 17/6/2026 | Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way. | |
| Modificada | Alta (8.8) | 1.8% | — | Apache Superset | 18/10/2021 | 17/6/2026 | Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allowed SQL injection when a malicious authenticated user sends an http request with a custom URL. | |
| Modificada | Media (5.4) | 1.7% | — | Apache Superset | 18/10/2021 | 17/6/2026 | Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker with Explore access to save a chart with a malicious title, injecting html (including scripts) into the page. | |
| Modificada | Media (6.1) | 64% | — | Apache Superset | 27/4/2021 | 17/6/2026 | Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not checking user input for open redirects the URL shortener functionality would allow for a malicious user to create a short URL for a dashboard that could convince the user to click the link. | |
| Modificada | Media (5.4) | 86% | — | Apache Superset | 5/3/2021 | 17/6/2026 | Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the context of the user's browser. The javascript code will be… | |
| Modificada | Alta (8.1) | 2.0% | — | Apache Superset | 30/9/2020 | 17/6/2026 | In the course of work on the open source project it was discovered that authenticated users running queries against Hive and Presto database engines could access information via a number of templated fields including the contents of query description metadata database, the hashed version of the authenticated users’… | |
| Modificada | Alta (8.8) | 3.1% | — | Apache Superset | 17/9/2020 | 17/6/2026 | While investigating a bug report on Apache Superset, it was determined that an authenticated user could craft requests via a number of templated text fields in the product that would allow arbitrary access to Python’s `os` package in the web application process in versions < 0.37.1. It was thus possible for an… | |
| Modificada | Media (6.5) | 1.4% | — | Apache Superset | 28/1/2020 | 17/6/2026 | An information disclosure issue was found in Apache Superset 0.34.0, 0.34.1, 0.35.0, and 0.35.1. Authenticated Apache Superset users are able to retrieve other users' information, including hashed passwords, by accessing an unused and undocumented API endpoint on Apache Superset. | |
| Modificada | Media (5.3) | 2.8% | — | Apache Superset | 16/12/2019 | 17/6/2026 | In Apache Incubator Superset before 0.32, a user can view database names that he has no access to on a dropdown list in SQLLab | |
| Modificada | Media (5.3) | 2.8% | — | Apache Superset | 16/12/2019 | 17/6/2026 | In Apache Incubator Superset before 0.31 user could query database metadata information from a database he has no access to, by using a specially crafted complex query. | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Apache Superset | 7/11/2018 | 17/6/2026 | Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation. |