Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.38%—Thedaylightstudio Fuel CMS22/2/202417/6/2026
A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.
AnalizadaAlta (8.1)0.36%—Br-automation Automation StudioBr-automation Technology Guarding22/2/202417/6/2026
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.
ModificadaAlta (7.2)1.5%—Firebearstudio Improved Import & Export16/2/202417/6/2026
A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.
ModificadaAlta (7.5)2.7%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.5)2.4%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.5)0.38%—Br-automation Automation Studio2/2/202417/6/2026
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.
ModificadaAlta (7.8)0.15%—Br-automation Automation StudioBr-automation Automation Net/pvi2/2/202417/6/2026
Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP;…
ModificadaAlta (7.8)0.40%—Br-automation Automation Studio2/2/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
ModificadaAlta (8.8)0.15%—Br-automation Automation Studio2/2/202417/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP.
ModificadaAlta (7.5)0.54%—Seweurodrive Movitools Motionstudio1/2/202417/6/2026
When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.
ModificadaCrítica (9.8)1.6%—3DS Biovia Materials Studio1/2/202417/6/2026
An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.
ModificadaMedia (5.3)0.74%—Humansignal Label Studio31/1/202417/6/2026
Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on version 1.8.2. Label Studio's SSRF protections that can be enabled by setting the `SSRF_PROTECTION_ENABLED` environment variable can be bypassed to access internal web…
ModificadaAlta (7.8)0.16%—Progress Telerik Test Studio31/1/202417/6/2026
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate…
ModificadaMedia (5.3)0.95%💥 PoCStrangerstudios Paid Memberships PRO25/1/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible…
ModificadaMedia (6.1)0.59%—Humansignal Label Studio24/1/202417/6/2026
Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. Prior to version 1.10.1, this feature could had been abused to download a HTML file that executed malicious JavaScript code in the…
ModificadaMedia (5.4)1.4%💥 ExploitHumansignal Label Studio23/1/202417/6/2026
Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could…
ModificadaAlta (7.8)0.33%—Omron Sysmac Studio22/1/202417/6/2026
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.
ModificadaCrítica (9.8)1.00%—Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+1119/1/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long…
ModificadaCrítica (9.8)0.39%—Studionetworksolutions Sharebrowser17/1/202417/6/2026
Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.
ModificadaAlta (7.8)0.26%—Facebook Meta Spark Studio16/1/202417/6/2026
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
ModificadaMedia (5.3)0.51%—Strangerstudios Paid Memberships PRO11/1/202417/6/2026
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up…
ModificadaAlta (7.8)0.27%—Omron Automation Software Sysmac Studio10/1/202417/6/2026
Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
ModificadaAlta (7.8)0.49%—Schneider-electric Easergy Studio9/1/202417/6/2026
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
ModificadaMedia (6.8)2.9%—Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 20229/1/202417/6/2026
Microsoft Identity Denial of service vulnerability
ModificadaAlta (7.8)3.9%💥 PoCMicrosoft Visual StudioMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 20229/1/202417/6/2026
Visual Studio Elevation of Privilege Vulnerability