Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.30% | — | Keyence KV Replay ViewerKeyence KV StudioKeyence Vt5-wx15 FirmwareKeyence Vt5-wx12 Firmware | 15/4/2024 | 17/6/2026 | Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |
| Analizada | Alta (8.8) | 0.85% | — | Keyence KV Replay ViewerKeyence KV StudioKeyence Vt5-wx15 FirmwareKeyence Vt5-wx12 Firmware | 15/4/2024 | 17/6/2026 | Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to information disclosure or arbitrary code execution by having a user of the affected product open a specially crafted file. | |
| Analizada | Alta (7.8) | 0.19% | — | Keyence VT Studio | 15/4/2024 | 17/6/2026 | VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application. | |
| Modificada | Media (4.3) | 0.90% | 💥 PoC | Strangerstudios Paid Memberships PRO | 9/4/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.10. This is due to missing nonce validation on the pmpro_lifter_save_streamline_option() function. This makes it possible… | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server 2019Microsoft SQL Server 2022Microsoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 2.4% | — | Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft Odbc Driver FOR SQL ServerMicrosoft Visual Studio 2019+1 | 9/4/2024 | 17/6/2026 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 2.5% | 💥 PoC | Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 9/4/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Aplazada | Media (5.9) | 0.34% | — | Phpbits Creative Studio Easy Login StylerAI | 7/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Stored XSS.This issue affects Easy Login Styler – White Label Admin Login Page for WordPress: from n/a through 1.0.6. | |
| Aplazada | Alta (7.1) | 0.18% | — | Toastie Studio Woocommerce Social Media Share ButtonsAI | 2/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a through 1.3.0. | |
| Aplazada | Alta (8.5) | 0.49% | — | Whitestudio Easy Form BuilderAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhiteStudio Easy Form Builder.This issue affects Easy Form Builder: from n/a through 3.7.4. | |
| Modificada | Media (5.4) | 0.32% | — | La-studioweb La-studio Element KIT FOR Elementor | 14/3/2024 | 17/6/2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all versions up to, and including, 1.3.7.4 due to insufficient input sanitization and output escaping the user supplied attribute. This makes it possible… | |
| Analizada | Alta (7.3) | 0.94% | — | Microsoft Azure Data Studio | 12/3/2024 | 17/6/2026 | Azure Data Studio Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 3.0% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+4 | 12/3/2024 | 17/6/2026 | Microsoft QUIC Denial of Service Vulnerability | |
| Analizada | Alta (8.8) | 1.9% | — | Microsoft Visual Studio Code | 12/3/2024 | 17/6/2026 | Visual Studio Code Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 3.1% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 12/3/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (4.3) | 0.55% | — | Strangerstudios Paid Memberships PRO | 11/3/2024 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata. | |
| Analizada | Media (6.1) | 2.2% | — | Humansignal Label Studio | 22/2/2024 | 17/6/2026 | ### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within a [`Choices`](https://labelstud.io/tags/choices) or [`Labels`](https://labelstud.io/tags/labels) tag, resulting in an XSS vulnerability. ### Details Need permission… |