Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
537 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.31% | — | Cysoft168 Super Easy Enterprise Management System | 15/8/2024 | 17/6/2026 | SQL Injection vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the/ajax/Login.ashx component. | |
| Modificada | Media (6.1) | 0.34% | — | Cysoft168 Super Easy Enterprise Management System | 15/8/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker to execute arbitrary code via a crafted script to the /WebSet/DlgGridSet.html component. | |
| Aplazada | Alta (8.8) | 0.40% | — | Superfly Responsive MenuAI | 2/8/2024 | 17/6/2026 | The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.29. This is due to missing or incorrect nonce validation on the ajax_handle_delete_icons() function. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.63% | — | SuperagiAI | 22/7/2024 | 17/6/2026 | All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server. | |
| Modificada | Media (5.4) | 0.28% | — | Supersaas | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SuperSaaS SuperSaaS – online appointment scheduling allows Stored XSS.This issue affects SuperSaaS – online appointment scheduling: from n/a through 2.1.9. | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Apache Superset | 16/7/2024 | 17/6/2026 | An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. To mitigate this, a new configuration key named… | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dph-tAISupermicro X11dph-tqAISupermicro X11dph-iAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4. | |
| Aplazada | Alta (7.5) | 0.15% | — | Supermicro X11dpg-hgx2AISupermicro X11pdg-qtAISupermicro X11pdg-otAISupermicro X11pdg-snAI | 15/7/2024 | 17/6/2026 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Supermicro BMC FirmwareAISupermicro X11AISupermicro X12AISupermicro H12AI+5 | 11/7/2024 | 17/6/2026 | An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM6 modules). An unauthenticated user can post crafted data to the interface that triggers a stack buffer overflow, and may lead to arbitrary remote code execution on a BMC. | |
| Modificada | Media (5.3) | 1.6% | 💥 PoC | Apache Superset | 20/6/2024 | 17/6/2026 | Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to… | |
| Modificada | Media (4.8) | 0.25% | — | LG Supersign CMS | 20/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1. | |
| Modificada | Media (4.8) | 0.25% | — | LG Supersign CMS | 20/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1. | |
| Modificada | Media (4.8) | 0.25% | — | LG Supersign CMS | 20/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electronics SuperSign CMS allows Reflected XSS. This issue affects SuperSign CMS: from 4.1.3 before < 4.3.1. | |
| Aplazada | Media (4.8) | 0.23% | — | LG Electronics LG Supersign CMSAI | 20/6/2024 | 17/6/2026 | Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanning.This issue affects LG SuperSign CMS: from 4.1.3 before < 4.3.1. | |
| Analizada | Media (4.3) | 0.70% | — | Apache Superset | 7/5/2024 | 17/6/2026 | An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, which fixes the issue. | |
| Analizada | Media (5.3) | 2.1% | — | LG Supersign Media Editor | 3/5/2024 | 17/6/2026 | LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The specific flaw… | |
| Analizada | Alta (7.5) | 2.5% | — | LG Supersign Media Editor | 3/5/2024 | 17/6/2026 | LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG SuperSign Media Editor. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Crítica (9.8) | 0.68% | — | Webbax SupernewsletterAI | 30/4/2024 | 17/6/2026 | SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components. | |
| Aplazada | Alta (7.8) | 0.60% | 💥 PoC | Superantisyware ProfessionalAI | 29/4/2024 | 17/6/2026 | An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the C:\Program Files\SUPERAntiSpyware folder. | |
| Aplazada | Media (6.1) | 0.43% | — | Super 8 Live ChatAI | 29/4/2024 | 17/6/2026 | Super 8 Live Chat online customer service platform fails to properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. When the message recipient views the message, they become susceptible to Cross-site Scripting (XSS) attacks. | |
| Aplazada | Media (6.4) | 0.38% | — | Webikon Superfaktura WoocommerceAI | 24/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in 2day.Sk, Webikon SuperFaktura WooCommerce.This issue affects SuperFaktura WooCommerce: from n/a through 1.40.3. | |
| Aplazada | Alta (7.1) | 0.51% | — | Looks Awesome Superfly MenuAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in looks_awesome Superfly Menu superfly-menu.This issue affects Superfly Menu: from n/a through <= 5.0.25. | |
| Aplazada | Alta (7.5) | 0.53% | — | Supermicro SMMAISupermicro Smm2AISupermicro FPCAI | 15/4/2024 | 17/6/2026 | An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to exposure of limited system information. | |
| Analizada | Media (4.8) | 0.50% | — | Heateor Super Socializer | 15/4/2024 | 17/6/2026 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |