Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio 2026 | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio Code | 8/9/2026 | 11/9/2026 | Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (5.9) | 0.62% | — | Microsoft Visual Studio Code | 8/9/2026 | 23/9/2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.76% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.1) | 0.50% | — | Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | |
| En análisis | Alta (8.8) | 0.91% | — | Microsoft Visual StudioAI | 8/9/2026 | 29/9/2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.84% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.9) | 0.88% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 30/9/2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Media (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 7/9/2026 | 8/9/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… | |
| Aplazada | Crítica (9.2) | 0.57% | — | WebstudioAI | 5/9/2026 | 24/9/2026 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services,… | |
| Analizada | Crítica (10) | 0.49% | — | Microsoft Copilot Studio | 3/9/2026 | 8/9/2026 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (7.4) | 0.94% | — | Microsoft Discovery StudioAI | 3/9/2026 | 8/9/2026 | Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.3) | 0.41% | — | Label StudioAI | 3/9/2026 | 10/9/2026 | Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents. | |
| Aplazada | Alta (8.4) | 0.40% | — | Label StudioAI | 3/9/2026 | 24/9/2026 | Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in… | |
| Aplazada | Media (6.4) | 0.19% | — | Jegstudio GutenverseAI | 25/8/2026 | 26/8/2026 | The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.7) | 0.52% | — | Label StudioAI | 24/8/2026 | 24/9/2026 | Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required… | |
| Aplazada | Media (5.3) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal… | |
| Aplazada | Media (5.1) | 0.76% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,… | |
| Aplazada | Media (5.6) | 0.21% | — | Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-key material to a file under the Home Assistant configuration directory before… | |
| Aplazada | Alta (8.6) | 0.50% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper… | |
| Aplazada | Media (6.9) | 0.46% | — | GITAIHome-assistant Blueprint StudioAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user… | |
| Aplazada | Alta (8.7) | 0.45% | — | Blueprint StudioAIHome-assistant Home AssistantAI | 18/8/2026 | 8/9/2026 | Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Edge22 Studios LTD GP PremiumAI | 18/8/2026 | 8/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. | |
| Aplazada | Alta (7.5) | 1.4% | — | Hermes-studioAI | 17/8/2026 | 9/9/2026 | Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint |