Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
1418 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel NUC Software Studio Service | 10/5/2023 | 17/6/2026 | Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access | |
| Modificada | Media (6.6) | 0.88% | — | Microsoft Visual Studio Code | 9/5/2023 | 17/6/2026 | Visual Studio Code Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.26% | — | Apple MacosApple Studio Display Firmware | 8/5/2023 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Studio Display Firmware Update 16.4. An app may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Alta (7.5) | 0.54% | — | Talend Studio | 28/4/2023 | 17/6/2026 | In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.5) | 0.35% | — | Webdevstudios Custom Post Type UI | 24/4/2023 | 17/6/2026 | The Custom Post Type UI WordPress plugin before 1.13.5 does not properly check for CSRF when sending the debug information to a user supplied email, which could allow attackers to make a logged in admin send such information to an arbitrary email address via a CSRF attack. | |
| Modificada | Media (4.8) | 0.37% | — | Electric Studio Client Login Project Electric Studio Client Login | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in James Irving-Swift Electric Studio Client Login plugin <= 0.8.1 versions. | |
| Modificada | Media (5.5) | 0.35% | — | Egostudiogroup Super Clean | 20/4/2023 | 17/6/2026 | An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field of the _default_.xml file. | |
| Modificada | Alta (7.8) | 0.38% | — | Egostudiogroup Super Clean | 14/4/2023 | 17/6/2026 | An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges via the update_info field of the _default_.xml file. | |
| Modificada | Crítica (9.8) | 2.6% | — | Timmystudios Change Color OF Keypad | 14/4/2023 | 17/6/2026 | Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage. | |
| Modificada | Crítica (9.8) | 1.5% | — | Timmystudios Fast Typing Keyboard | 14/4/2023 | 17/6/2026 | Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution. | |
| Modificada | Media (5.5) | 0.54% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | Visual Studio Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.68% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.56% | — | Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 0.44% | — | Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.5% | — | Microsoft .netMicrosoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | .NET DLL Hijacking Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft Visual Studio Code | 11/4/2023 | 17/6/2026 | Visual Studio Code Remote Code Execution Vulnerability | |
| Modificada | Alta (8.2) | 0.57% | — | Jenkins Visual Studio Code Metrics | 2/4/2023 | 17/6/2026 | Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (6.5) | 0.31% | — | Hasthemes WP Film Studio | 27/3/2023 | 17/6/2026 | The WP Film Studio WordPress plugin before 1.3.5 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.8) | 60% | — | Strangerstudios Paid Memberships PRO | 20/3/2023 | 17/6/2026 | The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query. | |
| Modificada | Media (5.4) | 0.53% | — | Rangerstudio Directus | 6/3/2023 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Instances relying on an allow-listed reset URL are vulnerable to an HTML injection attack through the use of query parameters in the reset URL. An attacker could exploit this to email users urls to the servers domain but which may contain… | |
| Modificada | Media (6.5) | 0.75% | — | Dataiku Data Science Studio | 1/3/2023 | 17/6/2026 | In Dataiku DSS 11.2.1, an attacker can download other Dataiku files that were uploaded to the myfiles section by specifying the target username in a download request. | |
| Modificada | Alta (7.8) | 0.44% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/2/2023 | 19/8/2026 | Vulnerabilidad de ejecución remota de código de Visual Studio | |
| Modificada | Alta (7.8) | 0.52% | — | Microsoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/2/2023 | 19/8/2026 | Vulnerabilidad de ejecución remota de código de Visual Studio |