Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 11/8/2026 | 17/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 8/9/2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 11/8/2026 | 13/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio Code | 11/8/2026 | 24/9/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (6.5) | 0.34% | — | Humansignal Label StudioAI | 11/8/2026 | 3/9/2026 | A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use… | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | Ruby LSPAIMicrosoft Visual Studio CodeAI | 7/8/2026 | 18/9/2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager executables, or the Bundler `Gemfile` used at startup. A malicious repository containing… | |
| Analizada | Alta (8.3) | 0.14% | 💥 PoC | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Aplazada | Crítica (9.3) | 0.84% | — | Opencode StudioAI | 4/8/2026 | 16/9/2026 | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate… | |
| Aplazada | Media (6.4) | 0.26% | — | Strangerstudios Paid Memberships PROAI | 28/7/2026 | 28/7/2026 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input sanitization and output… | |
| Aplazada | Alta (7.1) | 0.25% | — | Whitestudio Easy Form BuilderAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Easy Form Builder <= 4.0.12 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | La-studioweb Element KIT FOR ElementorAI | 23/7/2026 | 30/9/2026 | Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. |