Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1418 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.8%—Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net9/1/202417/6/2026
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
ModificadaAlta (8.7)1.2%—Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+29/1/202417/6/2026
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
ModificadaCrítica (9.8)0.61%—Dataiku Data Science Studio9/1/202417/6/2026
Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass.
ModificadaAlta (7.5)0.48%—Studiowombat WP Optin Wheel8/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3.
ModificadaMedia (6.1)0.41%—Acumos Design Studio2/1/202417/6/2026
A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The name of the patch is…
ModificadaAlta (7.5)0.53%—Boxystudio Booked28/12/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4.
ModificadaAlta (7.8)0.45%—Ezviz Studio4/12/202317/6/2026
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
ModificadaAlta (8.8)51%—Strangerstudios Paid Memberships PRO18/11/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or…
ModificadaMedia (5.5)1.1%—Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/11/202317/6/2026
ASP.NET Core Security Feature Bypass Vulnerability
ModificadaAlta (7.5)2.8%—Microsoft Visual Studio 2022Microsoft Asp.net Core14/11/202317/6/2026
ASP.NET Core Denial of Service Vulnerability
ModificadaCrítica (9.8)13%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202214/11/202317/6/2026
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
ModificadaMedia (5.5)0.79%—Microsoft Visual Studio 2019Microsoft Visual Studio 202214/11/202317/6/2026
Visual Studio Denial of Service Vulnerability
ModificadaAlta (7.5)4.1%💥 ExploitHumansignal Label Studio13/11/202317/6/2026
Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by…
ModificadaMedia (4.7)0.44%—Clickstudios Passwordstate13/11/202317/6/2026
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to…
ModificadaAlta (8.8)0.36%—Strangerstudios Force Display Name12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions.
ModificadaAlta (8.8)1.2%—Humansignal Label Studio9/11/202317/6/2026
Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege…
ModificadaBaja (3.5)0.24%—Clickstudios Passwordstate31/10/202317/6/2026
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.
ModificadaMedia (5.4)0.45%—Strangerstudios Memberlite Shortcodes31/10/202317/6/2026
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such…
ModificadaMedia (5.4)0.40%—Prismtechstudios Modern Footnotes20/10/202317/6/2026
The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level…
ModificadaMedia (4.3)0.39%—Strangerstudios Paid Memberships PRO20/10/202317/6/2026
The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they…
ModificadaAlta (7.8)0.19%—Keyence KV Replay ViewerKeyence KV Studio11/10/202317/6/2026
Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file.
ModificadaAlta (7.5)70%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Windows 11 22h2Microsoft Windows Server 202210/10/202317/6/2026
Microsoft QUIC Denial of Service Vulnerability
ModificadaAlta (7.8)0.76%—Microsoft Azure Rtos Guix Studio10/10/202317/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5.4)0.38%—Boxystudio Cooked2/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions.