Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1416 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.48%—Microsoft Visual Studio Code14/7/202616/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.4)0.35%—Microsoft Visual Studio Code14/7/202616/7/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.5)0.87%—Microsoft Visual Studio Code14/7/202616/7/2026
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.5)0.47%—Microsoft Visual Studio Code14/7/202616/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (7.3)0.17%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to…
AnalizadaAlta (7.3)0.15%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a…
AnalizadaMedia (5.4)0.18%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the…
AplazadaCrítica (9.3)0.45%—Melograno Venture Studio AmeliaAI13/7/202613/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.4.2.
AplazadaAlta (7.5)0.96%—La-studio Element KITAI11/7/202614/7/2026
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on…
AplazadaMedia (5.3)0.30%—La-studio Element KITAI10/7/202610/7/2026
The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating an account through one of its unauthenticated AJAX actions, allowing unauthenticated attackers to register new accounts even when registration has been disabled…
Pendiente de análisisMedia (4.4)0.33%—Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI9/7/202614/7/2026
GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS…
AplazadaAlta (7.7)0.41%—Pimcore Studio Backend BundleAI9/7/202610/7/2026
Pimcore Studio Backend Bundle is the backend bundle for Pimcore Studio. Prior to 2025.4.6 and 2026.1.6, an authenticated user can extract the admin password hash and other database content through time-based blind SQL injection in the DateFilter column key parameter. The POST /pimcore-studio/api/website-settings…
Pendiente de análisisAlta (7.1)0.57%—Amazon Research AND Engineering StudioAI7/7/20268/7/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read…
AplazadaCrítica (9.5)0.65%💥 PoCGardyn Home KITAIGardyn StudioAI3/7/20266/7/2026
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns connection information for all Gardyn Home Kit and Studio devices. Access to this key also allows a malicious user to execute arbitrary commands on a specific…
AplazadaMedia (6.8)0.32%—Mendix Studio PROAI30/6/20262/7/2026
A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All versions), Mendix Studio Pro 10.14 (All versions), Mendix Studio Pro 10.15 (All versions), Mendix Studio Pro 10.16 (All versions), Mendix Studio Pro 10.17 (All versions),…
AplazadaBaja (1.3)0.33%—Cherryhq Cherry-studioAI29/6/202629/6/2026
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The…
AplazadaBaja (2.9)0.42%—Cherryhq Cherry-studioAI29/6/202630/6/2026
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The attack can be…
AplazadaMedia (4.4)0.40%—Jegstudio GutenverseAI27/6/202629/6/2026
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.3)0.30%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a size value exceeded the target type's range. This affects NI grpc-device 2.17.0 and prior versions.
AnalizadaCrítica (9.3)0.43%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an unauthenticated user access to the server on the local network. This affects NI grpc-device 2.17.0 and prior versions.
AnalizadaMedia (6)0.42%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhaustion. This affects NI grpc-device 2.17.0 and prior versions.
AnalizadaAlta (7.1)0.45%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigger invalid enum states and undefined behavior, potentially resulting in a denial of service. Successful exploitation requires an attacker to supply a specially crafted message containing an…
AnalizadaAlta (8.7)0.49%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attacker to cause a denial of service by triggering a crash. Successful exploitation requires an attacker to provide an unknown value to the data moniker service. This affects NI grpc-device 2.17.0 and…
AnalizadaAlta (8.7)0.49%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may result in a denial of service. Successful exploitation requires an attacker to supply a specially crafted write request. This affects NI grpc-device 2.17.0 and prior versions.
AnalizadaCrítica (9.3)0.80%—NI InstrumentstudioNI Grpc Device Server19/6/202625/6/2026
There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an attacker to cause an arbitrary memory dereference, potentially resulting in remote code execution. Successful exploitation requires an attacker to supply a specially crafted Moniker protobuf message.…
Orbitaley — Vulnerabilidades