Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.6) | 0.46% | — | Mendix Studio PROAI | 12/6/2025 | 28/9/2026 | A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions <… | |
| Aplazada | Alta (7.5) | 0.44% | — | Salesforce OmnistudioAI | 10/6/2025 | 17/6/2026 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254. | |
| Aplazada | Alta (7.5) | 0.43% | — | Salesforce OmnistudioAI | 10/6/2025 | 17/6/2026 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025. | |
| Aplazada | Media (5.3) | 0.42% | — | Salesforce OmnistudioAI | 10/6/2025 | 17/6/2026 | Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025 | |
| Aplazada | Crítica (9.1) | 0.49% | — | Salesforce OmnistudioAI | 10/6/2025 | 17/6/2026 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025 | |
| Aplazada | Alta (7.5) | 0.44% | — | Salesforce OmnistudioAI | 10/6/2025 | 17/6/2026 | Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025 | |
| Aplazada | Alta (8.8) | 0.44% | — | Teastudio WP Posts CarouselAI | 6/6/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carousel: from n/a through <= 1.3.12. | |
| Aplazada | Media (6.4) | 0.29% | — | La-studio Element KITAI | 30/5/2025 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (5.4) | 0.28% | — | La-studioweb Element KIT FOR Elementor | 30/5/2025 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.23% | — | Humansignal Label Studio ML Backend | 26/5/2025 | 17/6/2026 | A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load of the file label-studio-ml-backend/label_studio_ml/examples/yolo/utils/neural_nets.py of the component PT File… | |
| Modificada | Crítica (9.8) | 0.51% | — | Digitalzoomstudio Zoomsounds | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91. | |
| Aplazada | Alta (8.2) | 0.39% | — | Chimpstudio Jobhunt JOB AlertsAI | 23/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Chimpstudio Foodbakery Sticky CartAI | 19/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through <= 3.2. | |
| Analizada | Media (6.1) | 0.17% | — | Acugis Mapfig Studio | 15/5/2025 | 17/6/2026 | The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Alta (7.6) | 0.59% | 💥 Exploit | Humansignal Label Studio | 14/5/2025 | 17/6/2026 | Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The vulnerability… | |
| Analizada | Alta (8) | 1.2% | — | Microsoft Build ToolsMicrosoft Visual Studio 2022Microsoft .net | 13/5/2025 | 17/6/2026 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.5) | 0.46% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 13/5/2025 | 17/6/2026 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.62% | — | Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 13/5/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Azure AI Document Intelligence Studio | 13/5/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.1) | 0.75% | — | Microsoft Visual Studio Code | 13/5/2025 | 17/6/2026 | Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Aplazada | Media (4.3) | 0.24% | — | ContentstudioAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contentstudio: from n/a through <= 1.3.5. | |
| Analizada | Media (5.4) | 0.28% | — | Jegstudio Gutenverse | 29/4/2025 | 17/6/2026 | The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.9) | 0.22% | — | Devignstudiosltd Covid-19 Coronavirus Update Your CustomersAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.4) | 0.42% | — | La-studio Element KITAI | 18/4/2025 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.27% | — | Studio Hyperset THE Great Firewords OF ChinaAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China sensitive-chinese-words-scanner allows Stored XSS.This issue affects The Great Firewords of China: from n/a through <= 1.2. |