Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)7.4%—Cherry-ai Cherry Studio13/8/202517/6/2026
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in the oauth auth redirection endpoints and…
AnalizadaAlta (7.7)2.1%—Cherry-ai Cherry Studio13/8/202517/6/2026
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection during a connection with a malicious MCP server in HTTP Streamable mode. Attackers can setup a malicious MCP server with compatible OAuth authorization server…
AnalizadaAlta (7.8)3.2%—Microsoft Visual Studio 202212/8/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.6)0.77%—Cherry-ai Cherry Studio11/8/202517/6/2026
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a malicious website or embedding a specially crafted URL on any website. If a…
AplazadaMedia (6.4)0.31%—Jegstudio GutenverseAI6/8/202517/6/2026
The Gutenverse plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Animated Text and Fun Fact blocks in all versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaMedia (5.1)0.21%—Amazon Q DeveloperAIMicrosoft Visual Studio CodeAI30/7/202517/6/2026
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API…
AnalizadaMedia (5.9)0.15%—ARM Development Studio22/7/202517/6/2026
Uncontrolled Search Path Element in Arm Development Studio before 2025 may allow an attacker to perform a DLL hijacking attack. Successful exploitation could lead to local arbitrary code execution in the context of the user running Arm Development Studio.
AplazadaAlta (7.8)0.17%—TWO APP Studio JourneyAIApple IOSAI21/7/202517/6/2026
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5.5.6 on iOS allows local attackers to bypass biometric and PIN-based access control via repeated PIN attempts or dynamic code injection.
AplazadaMedia (5.5)0.09%—TWO APP Studio JourneyAI21/7/202517/6/2026
Unencrypted storage in the database in Two App Studio Journey v5.5.9 for iOS allows local attackers to extract sensitive data via direct access to the app’s filesystem.
AplazadaAlta (8.4)0.59%💥 ExploitVideocharge StudioAI16/7/202517/6/2026
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, leading to an SEH overwrite condition. An attacker can exploit this vulnerability…
AplazadaCrítica (10)80%💥 ExploitSawtooth Software Lighthouse StudioAI16/7/202517/6/2026
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciwweb.pl/ Perl web application. Exploitation allows an unauthenticated attacker can execute arbitrary commands.
AplazadaAlta (7)0.25%—Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI14/7/202517/6/2026
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
AnalizadaAlta (8.8)0.87%—Microsoft Visual StudioMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 20228/7/202517/6/2026
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.3)2.3%💥 ExploitAexol Studio Remote FOR MACAI3/7/202517/6/2026
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disabled (i.e., the "Allow unknown devices" option is enabled), the…
AplazadaMedia (6.5)0.45%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
AplazadaCrítica (9.1)0.40%—Getredhawkstudio File Manager Plugin FOR WordpressAI27/6/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file-manager-plugin-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects File Manager Plugin For Wordpress: from n/a through <= 7.5.
AplazadaAlta (8.1)0.60%—Tmrw-studio Katerio - MagazineAI27/6/202517/6/2026
Path Traversal vulnerability in TMRW-studio Katerio - Magazine allows PHP Local File Inclusion. This issue affects Katerio - Magazine: from n/a through 1.5.1.
AplazadaAlta (7.1)0.26%—Flexostudio Flexo CounterAI27/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Counter flexo-countdown allows Reflected XSS.This issue affects Flexo Counter: from n/a through <= 1.0001.
AnalizadaCrítica (9.1)0.44%—Digitalzoomstudio Zoomsounds25/6/202517/6/2026
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.
AplazadaAlta (8.8)0.36%—Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+124/6/202517/6/2026
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for…
AplazadaMedia (6.5)0.23%—Prismtechstudios Modern-footnotesAI20/6/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prismtechstudios Modern Footnotes modern-footnotes allows Stored XSS.This issue affects Modern Footnotes: from n/a through <= 1.4.19.
AplazadaMedia (5.3)0.29%—ContentstudioAI20/6/202517/6/2026
Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contentstudio: from n/a through <= 1.3.7.
AnalizadaMedia (5.4)0.25%—Jegstudio Gutenverse News19/6/202517/6/2026
The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
AnalizadaAlta (7.1)11%—Microsoft Visual Studio 202213/6/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.5)1.1%—Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell13/6/202517/6/2026
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.