Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.38% | — | Thedaylightstudio Fuel CMS | 22/2/2024 | 17/6/2026 | A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter. | |
| Analizada | Alta (8.1) | 0.36% | — | Br-automation Automation StudioBr-automation Technology Guarding | 22/2/2024 | 17/6/2026 | B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data. | |
| Modificada | Alta (7.2) | 1.5% | — | Firebearstudio Improved Import & Export | 16/2/2024 | 17/6/2026 | A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file. | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 0.38% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | : Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12. | |
| Modificada | Alta (7.8) | 0.15% | — | Br-automation Automation StudioBr-automation Automation Net/pvi | 2/2/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP;… | |
| Modificada | Alta (7.8) | 0.40% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12. | |
| Modificada | Alta (8.8) | 0.15% | — | Br-automation Automation Studio | 2/2/2024 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0 before 4.9.4 SP. | |
| Modificada | Alta (7.5) | 0.54% | — | Seweurodrive Movitools Motionstudio | 1/2/2024 | 17/6/2026 | When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. | |
| Modificada | Crítica (9.8) | 1.6% | — | 3DS Biovia Materials Studio | 1/2/2024 | 17/6/2026 | An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution. | |
| Modificada | Media (5.3) | 0.74% | — | Humansignal Label Studio | 31/1/2024 | 17/6/2026 | Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior to 1.11.0 and was tested on version 1.8.2. Label Studio's SSRF protections that can be enabled by setting the `SSRF_PROTECTION_ENABLED` environment variable can be bypassed to access internal web… | |
| Modificada | Alta (7.8) | 0.16% | — | Progress Telerik Test Studio | 31/1/2024 | 17/6/2026 | In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate… | |
| Modificada | Media (5.3) | 0.95% | 💥 PoC | Strangerstudios Paid Memberships PRO | 25/1/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.12.7. This is due to missing or incorrect nonce validation on the pmpro_update_level_order() function. This makes it possible… | |
| Modificada | Media (6.1) | 0.59% | — | Humansignal Label Studio | 24/1/2024 | 17/6/2026 | Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was downloaded and could be viewed on the website. Prior to version 1.10.1, this feature could had been abused to download a HTML file that executed malicious JavaScript code in the… | |
| Modificada | Media (5.4) | 1.4% | 💥 Exploit | Humansignal Label Studio | 23/1/2024 | 17/6/2026 | Label Studio is an a popular open source data labeling tool. Versions prior to 1.9.2 have a cross-site scripting (XSS) vulnerability that could be exploited when an authenticated user uploads a crafted image file for their avatar that gets rendered as a HTML file on the website. Executing arbitrary JavaScript could… | |
| Modificada | Alta (7.8) | 0.33% | — | Omron Sysmac Studio | 22/1/2024 | 17/6/2026 | Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user. | |
| Modificada | Crítica (9.8) | 1.00% | — | Millionclues Admin CSS MUDeano AMP ToolboxUnihost Confirm DataAgence-press CSS Adder+11 | 19/1/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio WooVirtualWallet – A virtual wallet for WooCommerce, Long Watch Studio WooVIP – Membership plugin for WordPress and WooCommerce, Long… | |
| Modificada | Crítica (9.8) | 0.39% | — | Studionetworksolutions Sharebrowser | 17/1/2024 | 17/6/2026 | Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636. | |
| Modificada | Alta (7.8) | 0.26% | — | Facebook Meta Spark Studio | 16/1/2024 | 17/6/2026 | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application. | |
| Modificada | Media (5.3) | 0.51% | — | Strangerstudios Paid Memberships PRO | 11/1/2024 | 17/6/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to unauthorized modification of membership levels created by the plugin due to an incorrectly implemented capability check in the pmpro_rest_api_get_permissions_check function in all versions up… | |
| Modificada | Alta (7.8) | 0.27% | — | Omron Automation Software Sysmac Studio | 10/1/2024 | 17/6/2026 | Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user. | |
| Modificada | Alta (7.8) | 0.49% | — | Schneider-electric Easergy Studio | 9/1/2024 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object. | |
| Modificada | Media (6.8) | 2.9% | — | Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 2022 | 9/1/2024 | 17/6/2026 | Microsoft Identity Denial of service vulnerability | |
| Modificada | Alta (7.8) | 3.9% | 💥 PoC | Microsoft Visual StudioMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 9/1/2024 | 17/6/2026 | Visual Studio Elevation of Privilege Vulnerability |