Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 1.0% | — | Microsoft Visual Studio 2022 | 11/11/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | |
| Aplazada | Alta (8.9) | 0.14% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot. | |
| Aplazada | Alta (8.9) | 0.17% | — | Rockwellautomation Studio 5000 Simulation InterfaceAI | 11/11/2025 | 17/6/2026 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes. | |
| Aplazada | Alta (7.7) | 0.26% | — | Google Looker StudioAI | 10/11/2025 | 17/6/2026 | An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report. This… | |
| Aplazada | Alta (7.3) | 0.25% | — | Google Looker StudioAIGoogle BigqueryAI | 10/11/2025 | 17/6/2026 | A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.… | |
| Aplazada | Alta (7.6) | 0.31% | — | Google Looker StudioAIGoogle BigqueryAI | 10/11/2025 | 17/6/2026 | A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no… | |
| Aplazada | Media (5.3) | 0.31% | — | Amazon Research AND Engineering StudioAI | 6/11/2025 | 17/6/2026 | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users… | |
| Aplazada | Media (6.5) | 0.20% | — | Debuggers Studio Marquee Addons FOR ElementorAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Whitebox-studio ScapeAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= 1.5.13. | |
| Aplazada | Media (6.1) | 0.16% | — | Bambu StudioAI | 21/10/2025 | 17/6/2026 | Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a malicious component in… | |
| Aplazada | Crítica (9.8) | 1.00% | 💥 PoC | Ntlab Studio PpomAI | 18/10/2025 | 17/6/2026 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Aplazada | Media (6.5) | 0.27% | — | Strangerstudios Memberlite ShortcodesAI | 17/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1. | |
| Modificada | Crítica (9.9) | 66% | 💥 Exploit | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | |
| Analizada | Media (5.7) | 0.72% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.3) | 0.37% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (8.7) | 0.37% | — | Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI | 14/10/2025 | 17/6/2026 | A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods. | |
| Analizada | Crítica (9.6) | 0.47% | — | Cherry-ai Cherry Studio | 10/10/2025 | 17/6/2026 | Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded configuration data and directly executes the command within it. In the files… | |
| Aplazada | Media (6.6) | 0.35% | — | Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI | 3/10/2025 | 17/6/2026 | Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0. | |
| Analizada | Alta (7.1) | 0.14% | — | Keyence VT Studio | 2/10/2025 | 17/6/2026 | VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Analizada | Alta (7.1) | 0.14% | — | Keyence VT Studio | 2/10/2025 | 17/6/2026 | VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Aplazada | Alta (7.1) | 0.14% | — | KV StudioAI | 2/10/2025 | 17/6/2026 | KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Analizada | Alta (7.1) | 0.14% | — | Keyence VT Studio | 2/10/2025 | 17/6/2026 | VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Aplazada | Alta (8.4) | 0.18% | — | Keyence KV StudioAI | 2/10/2025 | 17/6/2026 | KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Aplazada | Alta (8.4) | 0.18% | — | KV StudioAIKV Vt5-wx15AIKV Vt5-wx12AI | 2/10/2025 | 17/6/2026 | KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product. | |
| Aplazada | Media (5.9) | 0.18% | — | Space Studio Click AND TweetAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click & Tweet allows Stored XSS. This issue affects Click & Tweet: from n/a through 0.8.9. |