Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

537 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.31%—Cysoft168 Super Easy Enterprise Management System15/8/202417/6/2026
SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component.
ModificadaMedia (6.1)0.34%—Cysoft168 Super Easy Enterprise Management System15/8/202417/6/2026
Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component.
AplazadaAlta (8.8)0.40%—Superfly Responsive MenuAI2/8/202417/6/2026
The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.63%—SuperagiAI22/7/202417/6/2026
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.
ModificadaMedia (5.4)0.28%—Supersaas21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SuperSaaS SuperSaaS – online appointment scheduling allows Stored XSS.This issue affects SuperSaaS – online appointment scheduling: from n/a through 2.1.9.
ModificadaCrítica (9.8)4.4%💥 ExploitApache Superset16/7/202417/6/2026
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named…
AplazadaAlta (7.5)0.15%—Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI15/7/202417/6/2026
An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.
AplazadaAlta (7.5)0.15%—Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI15/7/202417/6/2026
An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.
AplazadaAlta (7.5)0.15%—Supermicro X11dpg-hgx2AISupermicro X11pdg-qtAISupermicro X11pdg-otAISupermicro X11pdg-snAI15/7/202417/6/2026
An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4.
AplazadaCrítica (9.8)1.3%—Supermicro BMC FirmwareAISupermicro X11AISupermicro X12AISupermicro H12AI+511/7/202417/6/2026
An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC.
ModificadaMedia (5.3)1.6%💥 PoCApache Superset20/6/202417/6/2026
Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to…
ModificadaMedia (4.8)0.25%—LG Supersign CMS20/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
ModificadaMedia (4.8)0.25%—LG Supersign CMS20/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
ModificadaMedia (4.8)0.25%—LG Supersign CMS20/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1.
AplazadaMedia (4.8)0.23%—LG Electronics LG Supersign CMSAI20/6/202417/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanning.This issue affects LG SuperSign CMS: from 4.1.3 before < 4.3.1.
AnalizadaMedia (4.3)0.70%—Apache Superset7/5/202417/6/2026
An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue.
AnalizadaMedia (5.3)2.1%—LG Supersign Media Editor3/5/202417/6/2026
LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaAlta (7.5)2.5%—LG Supersign Media Editor3/5/202417/6/2026
LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The…
AplazadaCrítica (9.8)0.68%—Webbax SupernewsletterAI30/4/202417/6/2026
SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.
AplazadaAlta (7.8)0.60%💥 PoCSuperantisyware ProfessionalAI29/4/202417/6/2026
An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder.
AplazadaMedia (6.1)0.43%—Super 8 Live ChatAI29/4/202417/6/2026
Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks.
AplazadaMedia (6.4)0.38%—Webikon Superfaktura WoocommerceAI24/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a through 1.40.3.
AplazadaAlta (7.1)0.51%—Looks Awesome Superfly MenuAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Superfly Menu superfly-menu.This issue affects Superfly Menu: from n/a through <= 5.0.25.
AplazadaAlta (7.5)0.53%—Supermicro SMMAISupermicro Smm2AISupermicro FPCAI15/4/202417/6/2026
An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information.
AnalizadaMedia (4.8)0.50%—Heateor Super Socializer15/4/202417/6/2026
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed