Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 2.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 13/8/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft .netMicrosoft Visual Studio 2022 | 13/8/2024 | 17/6/2026 | .NET and Visual Studio Information Disclosure Vulnerability | |
| Aplazada | Media (6.5) | 0.26% | — | La-studioweb Element KIT FOR ElementorAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.9.2. | |
| Modificada | Media (6.5) | 12% | — | Microsoft Copilot Studio | 6/8/2024 | 17/6/2026 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. | |
| Analizada | Media (5.4) | 0.38% | — | Boxystudio Cooked | 5/8/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with… | |
| Modificada | Media (6.5) | 0.52% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector. | |
| Analizada | Media (4.9) | 0.56% | — | Strangerstudios Paid Memberships PRO | 30/7/2024 | 17/6/2026 | The pmpro-membership-maps WordPress plugin before 0.7 does not prevent users with at least the contributor role from leaking sensitive information about users with a membership on the site. | |
| Modificada | Media (5.4) | 0.25% | — | Jegstudio Gutenverse | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jegstudio Gutenverse allows Stored XSS.This issue affects Gutenverse: from n/a through 1.9.2. | |
| Analizada | Media (5.4) | 0.36% | — | Boxystudio Cooked | 18/7/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary… | |
| Analizada | Alta (8.8) | 0.38% | — | Boxystudio Cooked | 18/7/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an… | |
| Analizada | Alta (8.8) | 0.38% | — | Boxystudio Cooked | 18/7/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an… | |
| Analizada | Alta (8.8) | 0.39% | — | Boxystudio Cooked | 18/7/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an… | |
| Analizada | Alta (8.8) | 0.39% | — | Boxystudio Cooked | 18/7/2024 | 17/6/2026 | Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to, and including, 1.7.15.4 due to missing or incorrect nonce validation on the AJAX action handler. This vulnerability could allow an attacker to trick users into performing an action they… | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.3) | 1.3% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 2.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 2.9% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.2) | 0.74% | — | Strangerstudios Paid Memberships PRO | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5. | |
| Analizada | Alta (8.8) | 0.44% | — | La-studioweb Element KIT FOR Elementor | 2/7/2024 | 17/6/2026 | Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1. | |
| Modificada | Alta (8.8) | 0.95% | — | La-studioweb Element KIT FOR Elementor | 2/7/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the… | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.3) | 1.1% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/html) is used. An attacker may embed HTML tags directly in image data which is rendered by a webpage as HTML. This issue affects AdmirorFrames: before 5.0. | |
| Modificada | Alta (8.2) | 1.2% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. This issue affects AdmirorFrames: before 5.0. | |
| Modificada | Media (6.3) | 1.5% | 💥 PoC | Admiror-design-studio Admirorframes | 28/6/2024 | 17/6/2026 | Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects AdmirorFrames: before 5.0. | |
| Aplazada | Media (6.5) | 0.31% | — | Clickstudios PasswordstateAI | 24/6/2024 | 17/6/2026 | Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. |