Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.57%—Tmrw-studio AtlasAI8/1/20267/10/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TMRW-studio Atlas atlas allows PHP Local File Inclusion.This issue affects Atlas: from n/a through <= 2.1.0.
AplazadaCrítica (9.8)0.38%—Digitalzoomstudio DZS Video GalleryAI7/1/20267/10/2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.37.
AplazadaAlta (7.1)0.22%—Digitalzoomstudio DZS Video GalleryAI7/1/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital zoom studio DZS Video Gallery allows Reflected XSS.This issue affects DZS Video Gallery: from n/a through 12.25.
AplazadaAlta (8.8)0.35%—Digitalzoomstudio DZS Video GalleryAI6/1/20267/10/2026
Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS Video Gallery: from n/a through 12.25.
AplazadaAlta (7.1)0.18%—Digitalzoomstudio ZoomsoundsAI31/12/202523/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91.
AplazadaMedia (5.9)0.17%—Boxystudio CookedAI31/12/202523/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gora Tech Cooked cooked allows Stored XSS.This issue affects Cooked: from n/a through <= 1.11.3.
AplazadaMedia (4.3)0.24%—Yoohw Studio Order Cancellation ReturnsAI31/12/202523/9/2026
Authorization Bypass Through User-Controlled Key vulnerability in YoOhw Studio Order Cancellation & Returns for WooCommerce wc-order-cancellation-return allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Cancellation & Returns for WooCommerce: from n/a through <= 1.1.11.
AplazadaMedia (5.3)0.25%—Boxystudio CookedAI24/12/20257/10/2026
Missing Authorization vulnerability in Gora Tech Cooked cooked allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cooked: from n/a through <= 1.11.3.
AplazadaMedia (6.5)0.26%—Jegstudio Gutenverse FormAI24/12/20257/10/2026
Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.3.1.
AplazadaAlta (8.5)0.16%—Arcsoft PhotostudioAI19/12/202517/6/2026
Arcsoft PhotoStudio 6.0.0.172 contains an unquoted service path vulnerability in the ArcSoft Exchange Service that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted path and trigger the service to execute arbitrary code with system-level permissions.
AnalizadaMedia (6.1)0.22%—Microstudio15/12/202517/6/2026
A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.
AplazadaMedia (4.4)0.29%—Webdevstudios Custom Post Type UIAI13/12/202517/6/2026
The Custom Post Type UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'label' parameter during custom post type import in all versions up to, and including, 1.18.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.3)0.25%—Whitestudio Easy Form BuilderAI9/12/202517/6/2026
Missing Authorization vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form Builder: from n/a through <= 3.8.20.
AplazadaMedia (5.3)0.30%—Cridio Studio Listingpro Lead FormAI9/12/202517/6/2026
Missing Authorization vulnerability in CridioStudio ListingPro Lead Form listingpro-lead-form allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects ListingPro Lead Form: from n/a through <= 1.0.7.
AplazadaMedia (6.5)0.25%—Jegstudio Gutenverse NewsAI9/12/202517/6/2026
Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: from n/a through <=…
AplazadaCrítica (9.2)0.26%—Siemens ComosAISiemens JT Bi-directional Translator FOR StepAISiemens NXAISiemens Simcenter 3DAI+59/12/20257/10/2026
A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as…
AplazadaBaja (2.1)1.3%—Tykodev Cherry-studio-tykoforkAI7/12/202517/6/2026
A vulnerability has been found in TykoDev cherry-studio-TykoFork 0.1. This issue affects the function redirectToAuthorization of the file /.well-known/oauth-authorization-server of the component OAuth Server Discovery. Such manipulation of the argument authorizationUrl leads to os command injection. The attack can be…
AplazadaMedia (4.3)0.16%—ContentstudioAI5/12/202517/6/2026
The ContentStudio plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.7. This is due to missing or insufficient nonce validation on the add_cstu_settings function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request…
AplazadaAlta (8.8)0.61%—ContentstudioAI5/12/202517/6/2026
The ContentStudio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the cstu_update_post() function in all versions up to, and including, 1.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the…
AplazadaMedia (4.8)0.30%—Webdevstudios Custom Post Type UIAI4/12/202517/6/2026
The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.18.0. This is due to the plugin not verifying that a user has the required capability to perform actions in the "cptui_process_post_type" function. This makes it possible for authenticated…
AplazadaMedia (6.5)0.29%—Jegstudio Gutenverse FormAI21/11/202517/6/2026
Missing Authorization vulnerability in Jegstudio Gutenverse Form gutenverse-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse Form: from n/a through <= 2.2.0.
AplazadaMedia (6.5)0.24%—Jegstudio GutenverseAI21/11/202517/6/2026
Missing Authorization vulnerability in Jegstudio Gutenverse gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through <= 3.2.1.
ModificadaAlta (8)0.56%—Microsoft Visual Studio Code20/11/202517/6/2026
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
AplazadaMedia (5.3)0.32%—Bitplatform BoilerplateAIMicrosoft Visual StudioAIMicrosoft NETAI13/11/202517/6/2026
Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potentially allowing attackers to inject malicious scripts that compromise the security and integrity of web applications.…
AnalizadaMedia (5)0.42%—Microsoft Visual Studio Code11/11/202517/6/2026
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.