Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.48% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 1.2.3. | |
| Modificada | Media (5.4) | 0.22% | — | Strangerstudios Paid Memberships PRO | 19/6/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing or incorrect nonce validation on multiple functions. This makes it possible for unauthenticated… | |
| Analizada | Baja (1) | 0.11% | — | Google Bazel FOR Android StudioGoogle Bazel FOR ClionGoogle Bazel FOR Intellij | 18/6/2024 | 17/6/2026 | When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This comes from the fact that both call the method ProjectBuilder.createProject which then calls ProjectManager.getInstance().createProject. This method, as its name… | |
| Analizada | Media (5.4) | 0.43% | — | Boxystudio Cooked | 13/6/2024 | 17/6/2026 | The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with… | |
| Modificada | Alta (7.8) | 0.17% | — | Schneider-electric Easergy Studio | 12/6/2024 | 17/6/2026 | CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine. | |
| Modificada | Media (4.7) | 1.4% | 💥 PoC | Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/6/2024 | 20/7/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.7) | 0.89% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/6/2024 | 20/7/2026 | Visual Studio Elevation of Privilege Vulnerability | |
| Analizada | Media (6.8) | 0.18% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Analizada | Media (6.8) | 0.17% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. | |
| Modificada | Alta (8.8) | 0.36% | — | La-studioweb Element KIT FOR Elementor | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6. | |
| Aplazada | Media (6.4) | 0.43% | — | La-studio Element KITAI | 23/5/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Analizada | Alta (7.2) | 0.17% | — | Br-automation Automation Studio | 14/5/2024 | 17/6/2026 | Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product. | |
| Analizada | Media (5.9) | 1.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/5/2024 | 17/6/2026 | Visual Studio Denial of Service Vulnerability | |
| Analizada | Media (6.3) | 1.2% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/5/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Aplazada | Alta (7.8) | 15% | — | NI FlexloggerAINI InstrumentstudioAI | 14/5/2024 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior… | |
| Analizada | Media (6.1) | 0.44% | — | Jegstudio Gutenverse | 3/5/2024 | 17/6/2026 | The Gutenverse WordPress plugin before 1.9.1 does not validate the htmlTag option in various of its block before outputting it back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (5.3) | 0.57% | — | Tonjoostudio Easy Custom Auto ExcerptAI | 2/5/2024 | 17/6/2026 | The Easy Custom Auto Excerpt plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.12. This makes it possible for unauthenticated attackers to obtain excerpts of password-protected posts. | |
| Modificada | Media (4.3) | 0.30% | — | Strangerstudios Paid Memberships PRO | 2/5/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the pmpro_update_level_group_order() function. This makes it… | |
| Aplazada | Media (6.4) | 0.33% | — | La-studio Element KITAI | 2/5/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's LaStudioKit Post Author widget in all versions up to, and including, 1.3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.24% | — | Omron Cx-oneAIOmron Sysmac StudioAI | 1/5/2024 | 17/6/2026 | Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was installed with a DVD ver. 4.61.1 or lower, and was updated through CX-One V4 auto update in January 2024 or prior) and Sysmac Studio SYSMAC-SE2[][][] (The version which was installed with a DVD ver.… | |
| Aplazada | Media (6.1) | 0.96% | 💥 PoC | Beekeeperstudio Beekeeper StudioAI | 29/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container. | |
| Aplazada | Media (4.3) | 0.20% | — | Jegstudio FinancioAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jegstudio Financio.This issue affects Financio: from n/a through 1.1.3. | |
| Modificada | Alta (8.8) | 0.24% | — | Strangerstudios Paid Memberships PRO | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. | |
| Modificada | Alta (8.8) | 0.23% | — | Strangerstudios Paid Memberships PRO | 24/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10. | |
| Aplazada | Media (6.5) | 0.46% | — | Longwatchstudio MyrewardsAI | 22/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0. |