Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

537 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.21%—Superantispyware23/12/202517/6/2026
RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in…
AnalizadaAlta (7.8)0.21%—Superantispyware23/12/202517/6/2026
RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in…
AplazadaMedia (6.5)0.32%—Tyler Moore Super BlankAI18/12/202517/6/2026
Missing Authorization vulnerability in Tyler Moore Super Blank super-blank allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Blank: from n/a through <= 1.2.0.
ModificadaAlta (7.8)0.13%💥 PoCShirt-pocket Superduper!1/12/20255/7/2026
An issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary preflight script with root privileges and Full Disk Access, thus bypassing macOS privacy controls.
ModificadaAlta (7.8)0.11%💥 PoCShirt-pocket Superduper!1/12/20255/7/2026
An issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism
ModificadaAlta (8.1)0.30%💥 PoCShirt-pocket Superduper!1/12/20255/7/2026
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
AplazadaAlta (7.2)0.34%—Supermicro Mbd-x13sedw-fAI18/11/202517/6/2026
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to trigger the Stack buffer overflow vulnerability.
AplazadaMedia (5.5)0.32%—Supermicro BMCAI18/11/202517/6/2026
Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access to the BMC exploit stack buffer via a crafted header and achieve arbitrary code execution of the BMC’s firmware operating system.
AplazadaAlta (7.2)0.34%—Supermicro Mbd-x13sedw-fAI18/11/202517/6/2026
There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web server, an attacker can use a specially crafted payload to trigger the Stack buffer overflow vulnerability.
AplazadaMedia (5.4)0.23%—Supermicro BMCAIInsyde SmashAI13/11/202517/6/2026
Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability
AplazadaMedia (4.3)0.14%—Superstorefinder Super Store FinderAI29/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
AplazadaMedia (4.3)0.20%—SupervisorAI24/10/202517/6/2026
The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX functions in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update various plugin settings.
AplazadaAlta (7.1)0.30%—Ahmad Awais WP Super EditAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad Awais WP Super Edit wp-super-edit allows Reflected XSS.This issue affects WP Super Edit: from n/a through <= 2.5.4.
AplazadaCrítica (10)0.46%—Cmssuperheroes WastiaAI22/10/20255/10/2026
Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue affects Wastia: from n/a through < 1.1.3.
AplazadaCrítica (10)0.62%—Cmssuperheroes ClanoraAI22/10/20255/10/2026
Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanora: from n/a through < 1.3.1.
AplazadaAlta (8.3)0.55%—Sveltekit-superformsAI15/10/202517/6/2026
sveltekit-superforms makes SvelteKit forms a pleasure to use. sveltekit-superforms v2.27.3 and prior are susceptible to a prototype pollution vulnerability within the parseFormData function of formData.js. An attacker can inject string and array properties into Object.prototype, leading to denial of service, type…
AplazadaBaja (2.1)0.34%—Allstarlink SupermonAIAllstarlink Allmon2AI5/10/202517/6/2026
A security vulnerability has been detected in AllStarLink Supermon up to 6.2. This vulnerability affects unknown code of the component AllMon2. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early…
AplazadaMedia (6.5)0.28%—WOO Superb SlideshowAI3/10/202517/6/2026
The Woo superb slideshow transition gallery with random effect plugin for WordPress is vulnerable to SQL Injection via the 'woo-superb-slideshow' shortcode in all versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
AplazadaMedia (5.9)0.30%—Wpsuperiors WOO Additional Fees ON CheckoutAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPSuperiors Developer WooCommerce Additional Fees On Checkout (Free) woo-additional-fees-on-checkout-wordpress allows Stored XSS.This issue affects WooCommerce Additional Fees On Checkout (Free): from n/a through <=…
AplazadaAlta (7.2)0.31%—Supermicro Mbd-x12stwAISupermicro BMC FirmwareAI19/9/202517/6/2026
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X12STW . An attacker can update the system firmware with a specially crafted image.
AplazadaAlta (7.2)0.31%—Supermicro Mbd-x13sem-fAI19/9/202517/6/2026
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
AplazadaAlta (7.5)0.46%—Superstorefinder Super Store FinderAI9/9/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in highwarden Super Store Finder superstorefinder-wp allows PHP Local File Inclusion.This issue affects Super Store Finder: from n/a through < 7.8.
AnalizadaCrítica (9.3)0.52%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.
AnalizadaAlta (8.6)0.22%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.
AnalizadaCrítica (9.2)0.47%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.