Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

132 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.16%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaMedia (5.4)0.10%—Supsystic Photo GalleryAI30/9/202630/9/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
AplazadaAlta (7.1)0.18%—Supsystic PopupAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
AplazadaAlta (7.1)0.18%—Supsystic Ultimate MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.
AplazadaAlta (7.1)0.18%—Supsystic Easy Google MapsAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
AplazadaAlta (7.2)0.58%—Contact Form BY SupsysticAI5/9/20268/9/2026
The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (5.3)0.29%—Supsystic Ultimate MapsAI3/9/20265/9/2026
Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.
AplazadaAlta (7.5)1.9%—PhpsysinfoAI28/8/20269/9/2026
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these…
AplazadaCrítica (9.1)0.55%—Popup BY SupsysticAI18/8/202620/8/2026
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
AplazadaCrítica (9.8)0.56%—Supsystic PopupAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
AplazadaMedia (6.5)0.29%—Supsystic Contact FormAI18/8/202620/8/2026
Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.
AplazadaAlta (7.1)0.25%—Supsystic Contact FormAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions.
AplazadaAlta (7.5)0.35%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.1)0.25%—Supsystic Ultimate MapsAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions.
AplazadaAlta (7.2)0.33%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
AplazadaCrítica (9.8)0.56%—Supsystic Easy Google MapsAI18/8/202620/8/2026
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
AplazadaMedia (6.5)0.22%—Popup BY SupsysticAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.
AplazadaCrítica (9.8)0.55%—Supsystic PROAI6/8/202626/8/2026
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
AplazadaAlta (8.8)0.59%—Supsystic Smart PopupAI5/8/202612/8/2026
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method…
Pendiente de análisisAlta (8.7)0.34%—Synopsys Coverity ConnectAI29/7/202630/7/2026
A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized commands.
Pendiente de análisisCrítica (9.2)0.50%—Synopsys Coverity ConnectAIVmware Spring SecurityAI29/7/202630/7/2026
A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on certain API endpoints to access data…
AplazadaMedia (5.9)0.24%—Supsystic Photo GalleryAI23/7/202623/7/2026
Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions.
AplazadaMedia (6.9)0.67%—Supsystic BackupAI16/5/202629/9/2026
Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access sensitive files like…
AplazadaAlta (8.7)0.50%—Supsystic Digital PublicationsAI16/5/202629/9/2026
Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stored cross-site…