Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.48%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3.
ModificadaMedia (5.4)0.22%—Strangerstudios Paid Memberships PRO19/6/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated…
AnalizadaBaja (1)0.11%—Google Bazel FOR Android StudioGoogle Bazel FOR ClionGoogle Bazel FOR Intellij18/6/202417/6/2026
When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name…
AnalizadaMedia (5.4)0.43%—Boxystudio Cooked13/6/202417/6/2026
The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with…
ModificadaAlta (7.8)0.17%—Schneider-electric Easergy Studio12/6/202417/6/2026
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
ModificadaMedia (4.7)1.4%💥 PoCMicrosoft Visual Studio 2019Microsoft Visual Studio 202211/6/202420/7/2026
Visual Studio Remote Code Execution Vulnerability
ModificadaMedia (6.7)0.89%—Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 202211/6/202420/7/2026
Visual Studio Elevation of Privilege Vulnerability
AnalizadaMedia (6.8)0.18%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
AnalizadaMedia (6.8)0.17%—HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+2210/6/202417/6/2026
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
ModificadaAlta (8.8)0.36%—La-studioweb Element KIT FOR Elementor10/6/202417/6/2026
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6.
AplazadaMedia (6.4)0.43%—La-studio Element KITAI23/5/202417/6/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AnalizadaAlta (7.2)0.17%—Br-automation Automation Studio14/5/202417/6/2026
Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product.
AnalizadaMedia (5.9)1.7%—Microsoft .netMicrosoft Visual Studio 202214/5/202417/6/2026
Visual Studio Denial of Service Vulnerability
AnalizadaMedia (6.3)1.2%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/5/202417/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
AplazadaAlta (7.8)15%—NI FlexloggerAINI InstrumentstudioAI14/5/202417/6/2026
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior…
AnalizadaMedia (6.1)0.44%—Jegstudio Gutenverse3/5/202417/6/2026
The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaMedia (5.3)0.57%—Tonjoostudio Easy Custom Auto ExcerptAI2/5/202417/6/2026
The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts.
ModificadaMedia (4.3)0.30%—Strangerstudios Paid Memberships PRO2/5/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it…
AplazadaMedia (6.4)0.33%—La-studio Element KITAI2/5/202417/6/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (5.9)0.24%—Omron Cx-oneAIOmron Sysmac StudioAI1/5/202417/6/2026
Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver.…
AplazadaMedia (6.1)0.96%💥 PoCBeekeeperstudio Beekeeper StudioAI29/4/202417/6/2026
Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.
AplazadaMedia (4.3)0.20%—Jegstudio FinancioAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jegstudio Financio.This issue affects Financio: from n/a through 1.1.3.
ModificadaAlta (8.8)0.24%—Strangerstudios Paid Memberships PRO24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
ModificadaAlta (8.8)0.23%—Strangerstudios Paid Memberships PRO24/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.
AplazadaMedia (6.5)0.46%—Longwatchstudio MyrewardsAI22/4/202417/6/2026
Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.
Orbitaley — Vulnerabilidades