Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

537 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without…
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the tool controller. In affected source snapshots, get_tool and update_tool in superagi/controllers/tool.py accept a caller-supplied tool_id and fail to verify organization ownership through the associated toolkit. A remote authenticated…
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied agent_id or agent_execution_id values and do not verify that the…
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
SuperAGI up to v0.0.14 contains an improper access control vulnerability in the agent execution controller. In affected source snapshots, create_agent_execution and create_agent_run in superagi/controllers/agent_execution.py accept a caller-supplied agent_id and fail to verify that the referenced agent belongs to the…
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing agents belonging to a different organization without proper authorization checks. The endpoint accepts an agent_id…
AplazadaSin puntuar——SuperagiAI2/10/20262/10/2026
In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete agents belonging to a different organization's project.…
AplazadaAlta (8.8)0.30%—Super-forms Super FormsAI2/10/20262/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value…
AplazadaCrítica (9.1)0.88%—Super-forms Super FormsAI2/10/20262/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaAlta (8.1)0.54%—Super-forms Super FormsAI1/10/20261/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super…
AplazadaCrítica (9.8)0.29%—Super-forms Super FormsAI1/10/20261/10/2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that…
AplazadaBaja (2.1)0.32%—Zongxr SupermarketAI1/10/20261/10/2026
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The…
AplazadaMedia (5.5)0.44%—Zongxr SupermarketAI1/10/20261/10/2026
A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results…
AplazadaMedia (5.5)0.40%—Zongxr SupermarketAI1/10/20261/10/2026
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing…
AplazadaAlta (7.2)0.24%—Ifeelweb Affiliate Super AssistentAI1/9/20261/9/2026
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (7.1)0.25%—Superstorefinder Super Store FinderAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
AplazadaCrítica (9.8)0.47%—Super-diamond-serverAI26/8/202631/8/2026
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
AplazadaCrítica (9.8)0.61%—Super-diamond-serverAI26/8/202631/8/2026
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
AplazadaAlta (7.5)0.50%—Super-forms Super FormsAI24/8/202624/8/2026
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
AplazadaAlta (7.8)0.22%—Super ProductivityAIElectronAI18/8/202618/9/2026
Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in electron/ipc-handlers/exec.ts accepts a command string from the renderer through the IPC.EXEC channel and executes it with child_process.exec(). The electron/preload.ts…
AplazadaMedia (5.9)0.31%—Supertokens CoreAI7/8/20269/9/2026
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.
AplazadaAlta (7.1)0.25%—Heateor Super SocializerAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
AplazadaAlta (8.8)0.50%—Heateor Super SocializerAI6/8/202612/8/2026
Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
AplazadaMedia (5.5)0.53%—Heshengtao Super-agent-partyAI6/8/202612/8/2026
A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The…
AplazadaMedia (5.5)0.51%—Heshengtao Super-agent-partyAI6/8/202612/8/2026
A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit…
AplazadaMedia (4.4)0.31%—Super Progressive WEB AppsAI5/8/202612/8/2026
The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, 2.2.43. This is due to insufficient input sanitization and output escaping. The offline message value is stored without…