Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.8% | — | Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net | 9/1/2024 | 17/6/2026 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.7) | 1.2% | — | Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+2 | 9/1/2024 | 17/6/2026 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | |
| Modificada | Crítica (9.8) | 0.61% | — | Dataiku Data Science Studio | 9/1/2024 | 17/6/2026 | Dataiku DSS before 11.4.5 and 12.4.1 has Incorrect Access Control that could lead to a full authentication bypass. | |
| Modificada | Alta (7.5) | 0.48% | — | Studiowombat WP Optin Wheel | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3. | |
| Modificada | Media (6.1) | 0.41% | — | Acumos Design Studio | 2/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Acumos Design Studio up to 2.0.7. Affected is an unknown function. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.5) | 0.53% | — | Boxystudio Booked | 28/12/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BoxyStudio Booked - Appointment Booking for WordPress | Calendars.This issue affects Booked - Appointment Booking for WordPress | Calendars: from n/a before 2.4.4. | |
| Modificada | Alta (7.8) | 0.45% | — | Ezviz Studio | 4/12/2023 | 17/6/2026 | EzViz Studio v2.2.0 is vulnerable to DLL hijacking. | |
| Modificada | Alta (8.8) | 51% | — | Strangerstudios Paid Memberships PRO | 18/11/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'pmpro_paypalexpress_session_vars_for_user_fields' function in versions up to, and including, 2.12.3. This makes it possible for authenticated attackers with subscriber privileges or… | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | ASP.NET Core Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft Visual Studio 2022Microsoft Asp.net Core | 14/11/2023 | 17/6/2026 | ASP.NET Core Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 13% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 0.79% | — | Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Humansignal Label Studio | 13/11/2023 | 17/6/2026 | Label Studio is an open source data labeling tool. In all current versions of Label Studio prior to 1.9.2post0, the application allows users to insecurely set filters for filtering tasks. An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by… | |
| Modificada | Media (4.7) | 0.44% | — | Clickstudios Passwordstate | 13/11/2023 | 17/6/2026 | An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to… | |
| Modificada | Alta (8.8) | 0.36% | — | Strangerstudios Force Display Name | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stranger Studios Force First and Last Name as Display Name plugin <= 1.2 versions. | |
| Modificada | Alta (8.8) | 1.2% | — | Humansignal Label Studio | 9/11/2023 | 17/6/2026 | Label Studio is a multi-type data labeling and annotation tool with standardized output format. There is a vulnerability that can be chained within the ORM Leak vulnerability to impersonate any account on Label Studio. An attacker could exploit these vulnerabilities to escalate their privileges from a low privilege… | |
| Modificada | Baja (3.5) | 0.24% | — | Clickstudios Passwordstate | 31/10/2023 | 17/6/2026 | Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request. | |
| Modificada | Media (5.4) | 0.45% | — | Strangerstudios Memberlite Shortcodes | 31/10/2023 | 17/6/2026 | The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Media (5.4) | 0.40% | — | Prismtechstudios Modern Footnotes | 20/10/2023 | 17/6/2026 | The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level… | |
| Modificada | Media (4.3) | 0.39% | — | Strangerstudios Paid Memberships PRO | 20/10/2023 | 17/6/2026 | The Paid Memberships Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.2. This is due to missing or incorrect nonce validation on the pmpro_page_save() function. This makes it possible for unauthenticated attackers to save pages via a forged request granted they… | |
| Modificada | Alta (7.8) | 0.19% | — | Keyence KV Replay ViewerKeyence KV Studio | 11/10/2023 | 17/6/2026 | Out-of-bounds read vulnerability exists in KV STUDIO Ver. 11.62 and earlier and KV REPLAY VIEWER Ver. 2.62 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user of KV STUDIO PLAYER open a specially crafted file. | |
| Modificada | Alta (7.5) | 70% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Windows 11 22h2Microsoft Windows Server 2022 | 10/10/2023 | 17/6/2026 | Microsoft QUIC Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft Azure Rtos Guix Studio | 10/10/2023 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (5.4) | 0.38% | — | Boxystudio Cooked | 2/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Boxy Studio Cooked plugin <= 1.7.13 versions. |