Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
537 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.69% | — | Tencentmusic Supersonic | 3/4/2025 | 17/6/2026 | A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may… | |
| Aplazada | Alta (7.1) | 0.24% | — | Extendyourweb Super Responsive SliderAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendyourweb SUPER RESPONSIVE SLIDER super-slider allows Reflected XSS.This issue affects SUPER RESPONSIVE SLIDER: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.14% | — | Benoit DE Boeck WP SupersizedAI | 28/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Benoit De Boeck WP Supersized wp-supersized allows Cross Site Request Forgery.This issue affects WP Supersized: from n/a through <= 3.1.6. | |
| Aplazada | Media (4.3) | 0.20% | — | Hitoy Super Static CacheAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in hitoy Super Static Cache super-static-cache allows Cross Site Request Forgery.This issue affects Super Static Cache: from n/a through <= 3.3.5. | |
| Aplazada | Alta (7.6) | 0.55% | — | Marcel-nl Super Simple SubscriptionsAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marcel-NL Super Simple Subscriptions super-simple-subscriptions allows SQL Injection.This issue affects Super Simple Subscriptions: from n/a through <= 1.1.0. | |
| Analizada | Media (6.5) | 0.60% | — | Superagi | 20/3/2025 | 17/6/2026 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This could lead to… | |
| Analizada | Alta (8.8) | 1.2% | — | Superagi | 20/3/2025 | 17/6/2026 | SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system compromise. | |
| Modificada | Alta (7.5) | 0.81% | — | Superagi | 20/3/2025 | 17/6/2026 | SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request causes the server to continuously process each character. This… | |
| Modificada | Alta (8.8) | 0.62% | — | Superagi | 20/3/2025 | 17/6/2026 | In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover. | |
| Modificada | Media (6.5) | 0.60% | — | Superagi | 20/3/2025 | 17/6/2026 | In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover. | |
| Analizada | Alta (8.8) | 1.5% | — | Superagi | 20/3/2025 | 17/6/2026 | A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server. | |
| Analizada | Alta (8.8) | 0.73% | — | Superagi | 20/3/2025 | 17/6/2026 | An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints… | |
| Analizada | Alta (7.5) | 0.61% | — | Superagi | 20/3/2025 | 17/6/2026 | An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all information associated with… | |
| Analizada | Media (6.1) | 0.35% | — | Themepoints Super Testimonials | 18/2/2025 | 17/6/2026 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (8.8) | 0.52% | — | Apusthemes Superio | 12/2/2025 | 17/6/2026 | The Apus Framework plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'import_page_options' function in all versions up to, and including, 2.4. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Modificada | Crítica (9.8) | 0.66% | — | Apusthemes Superio | 12/2/2025 | 17/6/2026 | The WP Job Board Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.3.16. This is due to the plugin allowing a user to supply the 'role' field when registering. This makes it possible for unauthenticated attackers to register as an administrator on vulnerable sites. Please note that… | |
| Aplazada | Media (4.9) | 0.43% | — | SupersaasAI | 11/2/2025 | 17/6/2026 | The SuperSaaS – online appointment scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘after’ parameter in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Alta (7.5) | 0.39% | — | Superstorefinder Super Store Finder | 9/2/2025 | 17/6/2026 | The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all versions up to, and including, 7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.53% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with administrator privileges can upload a specially crafted image, which can cause a stack overflow due to the unchecked fat->fsd.max_fld. | |
| Aplazada | Alta (7.2) | 0.53% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack overflow is caused by not checking fld->used_bytes. | |
| Aplazada | Alta (7.2) | 0.25% | — | Supermicro Mbd-x12dpg-oa6AI | 4/2/2025 | 17/6/2026 | There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker can modify the firmware to bypass BMC inspection and bypass the signature verification process | |
| Aplazada | Media (4.3) | 0.34% | — | Xfinitysoft Content ClonerAIXfinitysoft Super SEO Content ClonerAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Xfinitysoft Content Cloner super-seo-content-cloner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Content Cloner: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.40% | — | Michael Super Block SliderAI | 24/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Michael Super Block Slider super-block-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Block Slider: from n/a through <= 2.7.9. | |
| Analizada | Media (5.3) | 0.44% | — | Heateor Super Socializer | 21/1/2025 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Alta (7.6) | 0.58% | — | Mindvalley Super PagemashAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mindvalley MindValley Super PageMash mindvalley-pagemash allows SQL Injection.This issue affects MindValley Super PageMash: from n/a through <= 1.1. |