Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1416 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.82%—Microsoft Visual Studio 20268/9/202611/9/2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.76%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net8/9/202611/9/2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.47%—Microsoft Visual Studio Code8/9/202611/9/2026
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AnalizadaMedia (5.9)0.62%—Microsoft Visual Studio Code8/9/202623/9/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7)0.76%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 20268/9/202629/9/2026
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.1)0.50%—Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 20268/9/202629/9/2026
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
En análisisAlta (8.8)0.91%—Microsoft Visual StudioAI8/9/202629/9/2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.84%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 20268/9/202629/9/2026
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (5.9)0.88%—Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net8/9/202630/9/2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AplazadaMedia (6.5)0.33%—Blog Studio Email Subscribers AND NewslettersAI7/9/20268/9/2026
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly…
AplazadaCrítica (9.2)0.57%—WebstudioAI5/9/202624/9/2026
Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services,…
AnalizadaCrítica (10)0.49%—Microsoft Copilot Studio3/9/20268/9/2026
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisAlta (7.4)0.94%—Microsoft Discovery StudioAI3/9/20268/9/2026
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (8.3)0.41%—Label StudioAI3/9/202610/9/2026
Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream bucket contents.
AplazadaAlta (8.4)0.40%—Label StudioAI3/9/202624/9/2026
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in…
AplazadaMedia (6.4)0.19%—Jegstudio GutenverseAI25/8/202626/8/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.7)0.52%—Label StudioAI24/8/202624/9/2026
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required…
AplazadaMedia (5.3)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal…
AplazadaMedia (5.1)0.76%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py accepted a cwd working-directory parameter and checked only whether the directory existed,…
AplazadaMedia (5.6)0.21%—Blueprint StudioAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote SSH private-key material to a file under the Home Assistant configuration directory before…
AplazadaAlta (8.6)0.50%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in custom_components/blueprint_studio/backend/git_manager.py by interpolating the configured Git username and token directly into executable helper…
AplazadaMedia (6.9)0.46%—GITAIHome-assistant Blueprint StudioAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git credentials, causing Git credential-store to persist usernames and access tokens in plaintext in the .git-credentials file for the user…
AplazadaAlta (8.7)0.45%—Blueprint StudioAIHome-assistant Home AssistantAI18/8/20268/9/2026
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any authenticated Home Assistant user because the backend did not consistently enforce the panel's admin-only authorization boundary. Affected…
AplazadaCrítica (9.9)0.48%—Edge22 Studios LTD GP PremiumAI18/8/20268/9/2026
Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.
AplazadaAlta (7.5)1.4%—Hermes-studioAI17/8/20269/9/2026
Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in api/hermes/download endpoint