Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
537 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.70% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on Windows. | |
| Analizada | Alta (7.2) | 18% | 💥 PoC | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user with BMC administrative privileges. | |
| Analizada | Alta (8.3) | 0.60% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.60% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.60% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Media (6.5) | 0.63% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Analizada | Alta (8.3) | 0.79% | — | Supermicro X11ssm-f FirmwareSupermicro X11sae-f FirmwareSupermicro X11sse-f Firmware | 27/3/2024 | 17/6/2026 | An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue. | |
| Modificada | Media (6.1) | 0.19% | — | Optimole Super Page Cache | 21/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5. | |
| Aplazada | Media (6.1) | 0.42% | — | Inforest Communications SupercaliAI | 5/3/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page. | |
| Analizada | Alta (7.5) | 0.45% | — | Webbax Super Newsletter | 3/3/2024 | 17/6/2026 | An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information. | |
| Modificada | Media (5.4) | 0.87% | — | Apache Superset | 28/2/2024 | 17/6/2026 | A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these charts and dashboards would still be subject to validation… | |
| Modificada | Media (6.5) | 0.73% | — | Apache Superset | 28/2/2024 | 17/6/2026 | Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to unauthorized data. This issue affects Apache Superset: before… | |
| Modificada | Media (6.5) | 0.78% | — | Apache Superset | 28/2/2024 | 17/6/2026 | Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which fixes the issue. | |
| Modificada | Media (4.3) | 0.95% | — | Apache Superset | 28/2/2024 | 17/6/2026 | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue. | |
| Analizada | Media (4.3) | 0.98% | — | Apache Superset | 28/2/2024 | 17/6/2026 | An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an error on the database. This error is not properly handled by Apache Superset and may inadvertently surface in the error log of the Alert exposing possibly… | |
| Modificada | Alta (8.1) | 0.54% | — | Superfaktura Woocommerce | 26/2/2024 | 17/6/2026 | The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations… | |
| Modificada | Media (6.5) | 1.7% | — | Apache Superset | 14/2/2024 | 17/6/2026 | This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets. This vulnerability exists in Apache Superset versions up to and… | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Superwebmailer | 7/2/2024 | 17/6/2026 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | |
| Modificada | Alta (7.8) | 0.27% | 💥 PoC | Binhdrm26 Super Reboot | 6/2/2024 | 17/6/2026 | The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device to send unauthorized broadcasts, leading to unintended consequences. The vulnerability is particularly concerning because these… | |
| Modificada | Alta (7.8) | 0.27% | — | Binhdrm26 Super Reboot | 6/2/2024 | 17/6/2026 | An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted intent | |
| Modificada | Media (5.5) | 0.24% | — | Realdefen Superantispyware | 29/1/2024 | 17/6/2026 | SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys driver. | |
| Modificada | Media (5.4) | 0.84% | — | Apache Superset | 23/1/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a script or add a specific HTML snippet that would act as a stored XSS. For 2.X versions, users should change their config to include:… | |
| Modificada | Media (6.1) | 0.31% | — | Super-forms Super Forms | 16/1/2024 | 17/6/2026 | The Super Forms - Drag & Drop Form Builder WordPress plugin before 6.0.4 does not escape the bob_czy_panstwa_sprawa_zostala_rozwiazana parameter before outputting it back in an attribute via the super_language_switcher AJAX action, leading to a Reflected Cross-Site Scripting. The action is also lacking CSRF, making… | |
| Modificada | Media (5.5) | 0.14% | — | Skoda-auto Superb 3 Firmware | 12/1/2024 | 17/6/2026 | By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service of other vehicle components even when the vehicle is moving at a high speed. No safety critical functions affected. | |
| Modificada | Media (5.3) | 0.23% | — | Skoda-auto Superb 3 Firmware | 12/1/2024 | 17/6/2026 | The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows an attacker connected to the in-vehicle Wi-Fi network to cause denial-of-service of the infotainment system, when the certain preconditions are… |