Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.52% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734. | |
| Aplazada | Media (5.3) | 0.59% | — | Jegstudio GutenverseAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Jegstudio Gutenverse allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse: from n/a through 1.8.5. | |
| Aplazada | Media (6.5) | 0.57% | — | La-studioweb Element KIT FOR ElementorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through <= 1.1.5. | |
| Analizada | Media (4.3) | 0.32% | — | La-studioweb La-studio Element KIT FOR Elementor | 4/12/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.26% | — | Planetstudio Arca Payment GatewayAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Planet Studio ArCa Payment Gateway arca-payment-gateway allows Stored XSS.This issue affects ArCa Payment Gateway: from n/a through <= 1.3.1. | |
| Aplazada | Alta (7.1) | 0.35% | — | Wpoets Awesome StudioAI | 2/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpoets Awesome Studio awesome-studio allows Reflected XSS.This issue affects Awesome Studio: from n/a through <= 2.4.4. | |
| Aplazada | Alta (8.8) | 0.41% | — | Clickstudios PasswordstateAI | 29/11/2024 | 17/6/2026 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. | |
| Analizada | Crítica (9.6) | 0.96% | — | Microsoft Copilot Studio | 26/11/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | |
| Aplazada | Media (6.4) | 0.47% | — | Strangerstudios Memberlite ShortcodesAI | 23/11/2024 | 17/6/2026 | The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's memberlite_accordion shortcode in all versions up to, and including, 1.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 1.1% | — | La-studioweb Element KIT FOR Elementor | 23/11/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.2 via the _load_template function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the… | |
| Aplazada | Media (6.5) | 0.39% | — | Digitalzoomstudio ParallaxerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in digitalzoomstudio Parallaxer parallaxer-lite-parallax-effects-on-images allows Stored XSS.This issue affects Parallaxer: from n/a through <= 1.00. | |
| Analizada | Media (6.7) | 0.75% | — | Microsoft Visual Studio 2022 | 12/11/2024 | 17/6/2026 | Visual Studio Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 2.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 12/11/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 3.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 12/11/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Aplazada | Crítica (9.8) | 1.7% | — | Circontrol RaptionAIEV Charger PwrstudioAI | 8/11/2024 | 17/6/2026 | The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip. | |
| Analizada | Media (6.1) | 0.46% | — | Redhat Codeready StudioRedhat Jboss Enterprise Application PlatformRedhat Openstack PlatformRedhat Single Sign-on+1 | 7/11/2024 | 17/6/2026 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS)… | |
| Analizada | Alta (7.5) | 0.40% | — | HP Poly TC8 FirmwareHP Poly Tc10 FirmwareHP Poly Studio G7500 FirmwareHP Poly Studio X30 Firmware+4 | 5/11/2024 | 17/6/2026 | A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself. | |
| Analizada | Crítica (9.8) | 0.67% | — | Strangerstudios Paid Memberships PRO | 1/11/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | |
| Aplazada | Media (5.7) | 0.18% | — | Omron Sysmac StudioAI | 1/11/2024 | 17/6/2026 | Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is exploited, an attacker may access the program which is protected by Data Protection function. | |
| Aplazada | Alta (7.7) | 0.97% | — | SAS StudioAI | 30/10/2024 | 5/7/2026 | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is disputed by the vendor because these filesystem paths are allowed for authorized users. | |
| Aplazada | Alta (8.8) | 0.62% | — | SAS StudioAI | 30/10/2024 | 5/7/2026 | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file upload is allowed for authorized users. | |
| Aplazada | Alta (8.8) | 0.73% | — | SAS StudioAI | 30/10/2024 | 5/7/2026 | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is disputed by the vendor because SQL statement execution is allowed for authorized users. | |
| Analizada | Media (4.8) | 0.35% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scripting vulnerability. If crafted input is stored by an administrative user, malicious script may be executed on the web browsers of other victim users. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. | |
| Analizada | Media (6.1) | 0.36% | — | Toshibatec E-studio1058 FirmwareToshibatec E-studio1208 FirmwareToshibatec E-studio908 FirmwareSharp Bp-90c70 Firmware+316 | 25/10/2024 | 17/6/2026 | Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser. |