Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.35% | — | Digitalzoomstudio DZS Ajaxer LiteAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio DZS Ajaxer Lite dzs-ajaxer-lite-dynamic-page-load allows Stored XSS.This issue affects DZS Ajaxer Lite: from n/a through <= 1.04. | |
| Aplazada | Alta (7.1) | 0.28% | — | Flexostudio Flexo SliderAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flexostudio Flexo Slider flexo-slider allows Reflected XSS.This issue affects Flexo Slider: from n/a through <= 1.0013. | |
| Analizada | Alta (7.7) | 0.67% | — | Humansignal Label Studio | 14/2/2025 | 17/6/2026 | Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's S3 storage integration feature contains a Server-Side Request Forgery (SSRF) vulnerability in its endpoint configuration. When creating an S3 storage connection, the application allows users to specify a custom S3 endpoint URL… | |
| Analizada | Media (6.1) | 1.9% | 💥 Exploit | Humansignal Label Studio | 14/2/2025 | 17/6/2026 | Label Studio is an open source data labeling tool. Prior to version 1.16.0, Label Studio's `/projects/upload-example` endpoint allows injection of arbitrary HTML through a `GET` request with an appropriately crafted `label_config` query parameter. By crafting a specially formatted XML label config with inline task… | |
| Aplazada | Alta (8.7) | 0.76% | — | Label StudioAILabel Studio SDKAI | 14/2/2025 | 17/6/2026 | Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to 1.0.10 allows unauthorized file access outside the intended directory structure. The flaw exists in the VOC, COCO and YOLO export functionalities. These functions invoke a `download` function on the… | |
| Analizada | Media (5.4) | 0.33% | — | Thedaylightstudio Fuel CMS | 12/2/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components. | |
| Analizada | Alta (7.3) | 0.71% | — | Microsoft Visual Studio Code | 11/2/2025 | 17/6/2026 | Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.76% | — | Microsoft Visual Studio Code | 11/2/2025 | 17/6/2026 | Visual Studio Code Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.3) | 0.69% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/2/2025 | 17/6/2026 | Visual Studio Installer Elevation of Privilege Vulnerability | |
| Aplazada | Media (5.9) | 0.29% | — | Coffeestudios POP UPAI | 7/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in coffeestudios Pop Up popup-seo-optimized allows Stored XSS.This issue affects Pop Up: from n/a through <= 0.1. | |
| Modificada | Alta (7.5) | 0.52% | — | Admiror-design-studio Admiror Gallery | 4/2/2025 | 5/7/2026 | Improper handling of input variables lead to multiple path traversal vulnerabilities in the Admiror Gallery extension for Joomla in version branch 4.x. | |
| Analizada | Alta (7.1) | 0.57% | 💥 Exploit | Canaveralstudio Justrows Free | 4/2/2025 | 17/6/2026 | The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Media (6.5) | 0.29% | — | Digitalzoomstudio Demo User DZSAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Demo User DZS demo-user-dzs-showcase-your-admin-safely allows Stored XSS.This issue affects Demo User DZS: from n/a through <= 1.1.0. | |
| Aplazada | Baja (2) | 0.20% | — | Obsproject OBS StudioAI | 20/1/2025 | 17/6/2026 | A vulnerability has been found in obsproject OBS Studio up to 30.0.2 on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to untrusted search path. The attack needs to be approached locally. The complexity of an attack is rather high. The… | |
| Analizada | Alta (7.3) | 0.52% | — | Microsoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | Visual Studio Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 2.3% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft .net Framework | 14/1/2025 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 1.2% | — | Microsoft Visual Studio 2022Microsoft .net | 14/1/2025 | 17/6/2026 | .NET Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 1.8% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | .NET Remote Code Execution Vulnerability | |
| Aplazada | Media (6.4) | 0.25% | — | Whitestudio Easy Form BuilderAI | 8/1/2025 | 17/6/2026 | The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'add_form_Emsfb' AJAX action in all versions up to, and including, 3.8.8 due to insufficient input… | |
| Aplazada | Media (4.3) | 0.20% | — | Digitalzoomstudio Admin Debug Wordpress Enable DebugAI | 7/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in digitalzoomstudio Admin debug wordpress – enable debug dzs-enable-debug allows Cross Site Request Forgery.This issue affects Admin debug wordpress – enable debug: from n/a through <= 1.0.13. | |
| Aplazada | Alta (7.1) | 0.26% | — | Lemonadestudio Lemonade Social Networks Autoposter PinterestAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lemonadestudio Lemonade Social Networks Autoposter Pinterest lemonade-sna-pinterest-edition allows Reflected XSS.This issue affects Lemonade Social Networks Autoposter Pinterest: from n/a through <= 2.0. | |
| Aplazada | Media (6.5) | 0.24% | — | Debuggers Studio SaaspricingAI | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debuggers Studio SaasPricing saaspricing allows DOM-Based XSS.This issue affects SaasPricing: from n/a through <= 1.2.4. | |
| Aplazada | Crítica (9.1) | 0.63% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714. |