Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.17% | — | IBM Watson Studio | 25/9/2025 | 17/6/2026 | IBM Watson Studio 4.0 through 5.2.0 on Cloud Pak for Data is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Alta (7.3) | 0.22% | — | Magnetism Studios EnduranceAI | 24/9/2025 | 25/9/2026 | A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:WithReply of the file /Applications/Endurance.app/Contents/Library/LaunchServices/com.MagnetismStudios.endurance.helper of the component NSXPC Interface. Executing manipulation can lead to missing… | |
| Aplazada | Media (6.5) | 0.20% | — | Coderz Studio Custom Iframe FOR ElementorAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Coderz Studio Custom iFrame for Elementor custom-iframe allows DOM-Based XSS.This issue affects Custom iFrame for Elementor: from n/a through <= 1.0.13. | |
| Aplazada | Media (5.9) | 0.22% | — | Anyclip Luminous StudioAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AnyClip Video Platform AnyClip Luminous Studio anyclip-media allows Stored XSS.This issue affects AnyClip Luminous Studio: from n/a through <= 1.3.3. | |
| Aplazada | Media (6.5) | 0.27% | — | Anyclip Luminous StudioAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AnyClip Video Platform AnyClip Luminous Studio anyclip-media allows Stored XSS.This issue affects AnyClip Luminous Studio: from n/a through <= 1.3.3. | |
| Aplazada | Media (6.4) | 0.28% | — | Strangerstudios Memberlite ShortcodesAI | 17/9/2025 | 25/9/2026 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.7) | 0.92% | — | Cloud Jasperreports IOCloud Jasperreports LibraryCloud Jasperreports ServerCloud Jasperreports Studio+1 | 16/9/2025 | 17/6/2026 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library | |
| Aplazada | Baja (3.2) | 0.15% | — | Clickstudios PasswordstateAI | 16/9/2025 | 30/9/2026 | Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL while on the Emergency Access web page, an unauthorized person can gain access to the Passwordstate Administration section. | |
| Aplazada | Media (6.4) | 0.20% | — | Embed Google DatastudioAI | 12/9/2025 | 17/6/2026 | The Embed Google Datastudio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'egds' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.92% | 💥 PoC | Microsoft Visual Studio Code | 12/9/2025 | 17/6/2026 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (8.8) | 0.33% | — | Webdevstudios Constant Contact FOR WordpressAI | 9/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in webdevstudios Constant Contact for WordPress allows Object Injection. This issue affects Constant Contact for WordPress: from n/a through 4.1.1. | |
| Aplazada | Media (6.4) | 0.24% | — | La-studio Element KITAI | 6/9/2025 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's widgets in all versions up to, and including, 1.5.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Crítica (9.2) | 0.85% | — | Ptzoptics Pt12x-sdi-xx-g2 FirmwarePtzoptics Pt12x-ndi-xx FirmwarePtzoptics Pt12x-usb-xx-g2 FirmwarePtzoptics Pt20x-sdi-xx-g2 Firmware+57 | 5/9/2025 | 17/6/2026 | PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative web interface. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Promptcraft Forge StudioAI | 4/9/2025 | 17/6/2026 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions contain an non-exhaustive URL scheme check that does not protect against XSS. User-controlled URLs pass through src/utils/validation.ts, but the check only strips `javascript:` and a few patterns.… | |
| Aplazada | Alta (8.2) | 0.24% | — | Promptcraft Forge StudioAI | 4/9/2025 | 17/6/2026 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All versions of Promptcraft Forge Studio sanitize user input using regex blacklists such as r`eplace(/javascript:/gi, '')`. Because the package uses multi-character tokens and each replacement is applied only… | |
| Aplazada | Media (6.3) | 0.24% | — | Coze-studioAI | 29/8/2025 | 17/6/2026 | A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument AuthSecretKey/StateSecretKey/OAuthTokenSecretKey leads to use of hard-coded cryptographic key . It is possible to initiate the attack… | |
| Analizada | Baja (1.1) | 0.22% | — | Seeedstudio Linkit Smart 7688 Firmware | 28/8/2025 | 25/9/2026 | A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached locally. A high degree of complexity is needed for the attack. The… | |
| Aplazada | Alta (8.4) | 0.49% | 💥 Exploit | Millenium MP3 StudioAI | 21/8/2025 | 16/6/2026 | Millenium MP3 Studio versions up to and including 2.0 is vulnerable to a stack-based buffer overflow when parsing .pls playlist files. The application fails to properly validate the length of the File1 field within the playlist, allowing an attacker to craft a malicious .pls file that overwrites the Structured… | |
| Aplazada | Alta (7.1) | 0.24% | — | Digitalzoomstudio Comments Capcha BOXAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Comments Capcha Box comments-capcha-box allows Reflected XSS.This issue affects Comments Capcha Box: from n/a through <= 1.1. | |
| Aplazada | Media (4.3) | 0.14% | — | Flexostudio Flexo-social-galleryAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in flexostudio flexo-social-gallery flexo-social-gallery allows Cross Site Request Forgery.This issue affects flexo-social-gallery: from n/a through <= 1.0006. | |
| Aplazada | Alta (7.3) | 0.13% | — | Rockwellautomation Studio 5000 Logix DesignerAI | 14/8/2025 | 17/6/2026 | A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicious code without triggering a crash. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Whitestudio Easy Form BuilderAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 3.8.15. | |
| Aplazada | Alta (8.1) | 0.54% | — | Octagonwebstudio Premium Addons FOR KingcomposerAIKing-theme KingcomposerAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in octagonwebstudio Premium Addons for KingComposer premium-addons-for-kingcomposer allows PHP Local File Inclusion.This issue affects Premium Addons for KingComposer: from n/a through <= 1.1.1. | |
| Aplazada | Crítica (9.3) | 0.49% | 💥 Exploit | Cytel StudioAI | 13/8/2025 | 16/6/2026 | Cytel Studio version 9.0 and earlier is vulnerable to a stack-based buffer overflow triggered by parsing a malformed .CY3 file. The vulnerability occurs when the application copies user-controlled strings into a fixed-size stack buffer (256 bytes) without proper bounds checking. Exploitation allows arbitrary code… | |
| Aplazada | Crítica (9.8) | 1.1% | 💥 PoC | Studio 3TAI | 13/8/2025 | 17/6/2026 | An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module |