Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.6)0.46%—Mendix Studio PROAI12/6/202528/9/2026
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (All versions < V11.13.0 for Mac), Mendix Studio Pro 11.12 (All versions <…
AplazadaAlta (7.5)0.44%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254.
AplazadaAlta (7.5)0.43%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025.
AplazadaMedia (5.3)0.42%—Salesforce OmnistudioAI10/6/202517/6/2026
Client-Side Enforcement of Server-Side Security vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of required permission check. This impacts OmniStudio: before Spring 2025
AplazadaCrítica (9.1)0.49%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for Salesforce objects. This impacts OmniStudio: before Spring 2025
AplazadaAlta (7.5)0.44%—Salesforce OmnistudioAI10/6/202517/6/2026
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmniStudio: before Spring 2025
AplazadaAlta (8.8)0.44%—Teastudio WP Posts CarouselAI6/6/202517/6/2026
Deserialization of Untrusted Data vulnerability in teastudio.pl WP Posts Carousel wp-posts-carousel allows Object Injection.This issue affects WP Posts Carousel: from n/a through <= 1.3.12.
AplazadaMedia (6.4)0.29%—La-studio Element KITAI30/5/202517/6/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Compare and Google Maps widgets in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AnalizadaMedia (5.4)0.28%—La-studioweb Element KIT FOR Elementor30/5/202517/6/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-lakit-element-link’ parameter in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (4.8)0.23%—Humansignal Label Studio ML Backend26/5/202517/6/2026
A vulnerability has been found in HumanSignal label-studio-ml-backend up to 9fb7f4aa186612806af2becfb621f6ed8d9fdbaf and classified as problematic. Affected by this vulnerability is the function load of the file label-studio-ml-backend/label_studio_ml/examples/yolo/utils/neural_nets.py of the component PT File…
ModificadaCrítica (9.8)0.51%—Digitalzoomstudio Zoomsounds23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.
AplazadaAlta (8.2)0.39%—Chimpstudio Jobhunt JOB AlertsAI23/5/202517/6/2026
Missing Authorization vulnerability in Chimpstudio JobHunt Job Alerts allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobHunt Job Alerts: from n/a through 3.6.
AplazadaCrítica (9.8)0.46%—Chimpstudio Foodbakery Sticky CartAI19/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through <= 3.2.
AnalizadaMedia (6.1)0.17%—Acugis Mapfig Studio15/5/202517/6/2026
The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaAlta (7.6)0.59%💥 ExploitHumansignal Label Studio14/5/202517/6/2026
Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks. The vulnerability…
AnalizadaAlta (8)1.2%—Microsoft Build ToolsMicrosoft Visual Studio 2022Microsoft .net13/5/202517/6/2026
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.46%—Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 202213/5/202517/6/2026
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.62%—Microsoft Visual Studio 2019Microsoft Visual Studio 202213/5/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.8)1.2%—Microsoft Azure AI Document Intelligence Studio13/5/202517/6/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.1)0.75%—Microsoft Visual Studio Code13/5/202517/6/2026
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AplazadaMedia (4.3)0.24%—ContentstudioAI7/5/202517/6/2026
Missing Authorization vulnerability in contentstudio Contentstudio contentstudio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contentstudio: from n/a through <= 1.3.5.
AnalizadaMedia (5.4)0.28%—Jegstudio Gutenverse29/4/202517/6/2026
The Gutenverse – Ultimate Block Addons and Page Builder for Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's countdown Block in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AplazadaMedia (5.9)0.22%—Devignstudiosltd Covid-19 Coronavirus Update Your CustomersAI24/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devignstudiosltd COVID-19 (Coronavirus) Update Your Customers covid-19-alert allows Stored XSS.This issue affects COVID-19 (Coronavirus) Update Your Customers: from n/a through <= 1.5.1.
AplazadaMedia (6.4)0.42%—La-studio Element KITAI18/4/202517/6/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Table of Contents widget in all versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (6.5)0.27%—Studio Hyperset THE Great Firewords OF ChinaAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Studio Hyperset The Great Firewords of China sensitive-chinese-words-scanner allows Stored XSS.This issue affects The Great Firewords of China: from n/a through <= 1.2.