Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.16% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Media (5.4) | 0.10% | — | Supsystic Photo GalleryAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic PopupAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Ultimate MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Supsystic Easy Google MapsAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions. | |
| Aplazada | Alta (7.2) | 0.58% | — | Contact Form BY SupsysticAI | 5/9/2026 | 8/9/2026 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.29% | — | Supsystic Ultimate MapsAI | 3/9/2026 | 5/9/2026 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3. | |
| Aplazada | Alta (7.5) | 1.9% | — | PhpsysinfoAI | 28/8/2026 | 9/9/2026 | phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these… | |
| Aplazada | Crítica (9.1) | 0.55% | — | Popup BY SupsysticAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic PopupAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | |
| Aplazada | Media (6.5) | 0.29% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Contact FormAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Supsystic Ultimate MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | |
| Aplazada | Alta (7.2) | 0.33% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Supsystic Easy Google MapsAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Popup BY SupsysticAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Supsystic PROAI | 6/8/2026 | 26/8/2026 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites. | |
| Aplazada | Alta (8.8) | 0.59% | — | Supsystic Smart PopupAI | 5/8/2026 | 12/8/2026 | The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method… | |
| Pendiente de análisis | Alta (8.7) | 0.34% | — | Synopsys Coverity ConnectAI | 29/7/2026 | 30/7/2026 | A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands. | |
| Pendiente de análisis | Crítica (9.2) | 0.50% | — | Synopsys Coverity ConnectAIVmware Spring SecurityAI | 29/7/2026 | 30/7/2026 | A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data… | |
| Aplazada | Media (5.9) | 0.24% | — | Supsystic Photo GalleryAI | 23/7/2026 | 23/7/2026 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | |
| Aplazada | Media (6.9) | 0.67% | — | Supsystic BackupAI | 16/5/2026 | 29/9/2026 | Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like… | |
| Aplazada | Alta (8.7) | 0.50% | — | Supsystic Digital PublicationsAI | 16/5/2026 | 29/9/2026 | Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site… |