Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)1.0%—Microsoft Visual Studio 202211/11/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
AplazadaAlta (8.9)0.14%—Rockwellautomation Studio 5000 Simulation InterfaceAI11/11/202517/6/2026
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.
AplazadaAlta (8.9)0.17%—Rockwellautomation Studio 5000 Simulation InterfaceAI11/11/202517/6/2026
A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.
AplazadaAlta (7.7)0.26%—Google Looker StudioAI10/11/202517/6/2026
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report. This…
AplazadaAlta (7.3)0.25%—Google Looker StudioAIGoogle BigqueryAI10/11/202517/6/2026
A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.…
AplazadaAlta (7.6)0.31%—Google Looker StudioAIGoogle BigqueryAI10/11/202517/6/2026
A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no…
AplazadaMedia (5.3)0.31%—Amazon Research AND Engineering StudioAI6/11/202517/6/2026
An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. To mitigate this issue, users…
AplazadaMedia (6.5)0.20%—Debuggers Studio Marquee Addons FOR ElementorAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio Marquee Addons for Elementor marquee-addons-for-elementor allows DOM-Based XSS.This issue affects Marquee Addons for Elementor: from n/a through <= 3.8.2.
AplazadaCrítica (9.8)0.58%—Whitebox-studio ScapeAI22/10/202517/6/2026
Deserialization of Untrusted Data vulnerability in Whitebox-Studio Scape scape allows Object Injection.This issue affects Scape: from n/a through <= 1.5.13.
AplazadaMedia (6.1)0.16%—Bambu StudioAI21/10/202517/6/2026
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a malicious component in…
AplazadaCrítica (9.8)1.00%💥 PoCNtlab Studio PpomAI18/10/202517/6/2026
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image cropper functionality in all versions up to, and including, 33.0.15. This makes it possible for unauthenticated attackers to upload arbitrary files on…
AplazadaMedia (6.5)0.27%—Strangerstudios Memberlite ShortcodesAI17/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.
ModificadaCrítica (9.9)66%💥 ExploitMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/10/202517/6/2026
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
AnalizadaMedia (5.7)0.72%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202214/10/202517/6/2026
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.3)0.37%—Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 202214/10/202517/6/2026
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.7)0.37%—Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI14/10/202517/6/2026
A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods.
AnalizadaCrítica (9.6)0.47%—Cherry-ai Cherry Studio10/10/202517/6/2026
Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded configuration data and directly executes the command within it. In the files…
AplazadaMedia (6.6)0.35%—Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI3/10/202517/6/2026
Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0.
AnalizadaAlta (7.1)0.14%—Keyence VT Studio2/10/202517/6/2026
VT STUDIO versions 8.53 and prior contain a use after free vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AnalizadaAlta (7.1)0.14%—Keyence VT Studio2/10/202517/6/2026
VT STUDIO versions 8.53 and prior contain an out-of-bounds read vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AplazadaAlta (7.1)0.14%—KV StudioAI2/10/202517/6/2026
KV STUDIO versions 12.23 and prior contain a buffer underflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AnalizadaAlta (7.1)0.14%—Keyence VT Studio2/10/202517/6/2026
VT Studio versions 8.53 and prior contain an access of uninitialized pointer vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AplazadaAlta (8.4)0.18%—Keyence KV StudioAI2/10/202517/6/2026
KV Studio versions 12.23 and prior contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AplazadaAlta (8.4)0.18%—KV StudioAIKV Vt5-wx15AIKV Vt5-wx12AI2/10/202517/6/2026
KV STUDIO and VT5-WX15/WX12 contain a stack-based buffer overflow vulnerability. If the product uses a specially crafted file, arbitrary code may be executed on the affected product.
AplazadaMedia (5.9)0.18%—Space Studio Click AND TweetAI26/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click & Tweet allows Stored XSS. This issue affects Click & Tweet: from n/a through 0.8.9.