Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
537 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.26% | — | Azzaroco WP SuperbackupAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Reflected XSS.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.4) | 0.37% | — | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.5) | 0.45% | — | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Alta (7.5) | 12% | 💥 PoC | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Aplazada | Crítica (10) | 35% | 💥 Exploit | Azzaroco WP SuperbackupAI | 31/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3. | |
| Modificada | Media (4.3) | 0.73% | — | Heateor Super Socializer | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54. | |
| Aplazada | Crítica (9.8) | 3.5% | 💥 PoC | Ibroid Super Backup CloneAI | 13/12/2024 | 17/6/2026 | The Super Backup & Clone - Migrate for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and a missing capability check on the ibk_restore_migrate_check() function in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers… | |
| Modificada | Alta (7.1) | 2.8% | — | Apache Superset | 12/12/2024 | 17/6/2026 | Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its execution. Non postgres analytics database connections and postgres analytics… | |
| Modificada | Alta (7.6) | 0.72% | — | Apache Superset | 9/12/2024 | 17/6/2026 | Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. | |
| Analizada | Media (5.3) | 0.85% | — | Apache Superset | 9/12/2024 | 17/6/2026 | Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue. | |
| Analizada | Baja (2.3) | 0.84% | — | Apache Superset | 9/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This issue is a follow-up to CVE-2024-39887 with additional… | |
| Aplazada | Media (4.3) | 0.61% | — | Super Progressive WEB AppsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21. | |
| Analizada | Crítica (9.8) | 0.46% | — | Mcafee Superscan | 11/11/2024 | 17/6/2026 | SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter. | |
| Aplazada | Alta (8.1) | 0.35% | — | Superfast Video DownloaderAIBluesky BrowserAI | 11/11/2024 | 17/6/2026 | The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component. | |
| Modificada | Media (5.4) | 0.26% | — | Themehat Super Addons FOR Elementor | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in riponhossain Super Addons for Elementor super-addons-for-elementor allows DOM-Based XSS.This issue affects Super Addons for Elementor: from n/a through <= 1.0. | |
| Analizada | Media (5.3) | 5.1% | — | Didi Super-jacoco | 6/11/2024 | 17/6/2026 | A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. The manipulation of the argument uuid leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Alta (8.1) | 0.63% | — | Heateor Super Socializer | 6/11/2024 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for… | |
| Aplazada | Media (5.3) | 1.2% | — | Didi Super-jacocoAI | 28/10/2024 | 17/6/2026 | A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation of the argument uuid leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (7.8) | 0.17% | — | Lenovo Superfile | 11/10/2024 | 17/6/2026 | A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges. | |
| Analizada | Media (5.4) | 0.35% | — | Codecabin Super Testimonials | 26/9/2024 | 17/6/2026 | The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (6.1) | 0.27% | — | Superstorefinder Super Store Finder | 18/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through <= 6.9.7. | |
| Modificada | Crítica (9.8) | 0.46% | — | Superstorefinder Super Store Finder | 17/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through < 6.9.8. | |
| Modificada | Crítica (9.8) | 0.46% | — | Superstorefinder Super Store Finder | 17/9/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through <= 6.9.7. | |
| Analizada | Alta (7.3) | 0.63% | — | Ifeelweb Affiliate Super Assistent | 10/9/2024 | 17/6/2026 | The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possible for… | |
| Modificada | Media (5.5) | 0.30% | — | Cysoft168 Super Easy Enterprise Management System | 15/8/2024 | 17/6/2026 | An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a single quotation mark. |