Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.15% | — | Jegstudio StartupzyAI | 17/6/2026 | 1/10/2026 | Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1. | |
| Analizada | Media (5.5) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 9/6/2026 | 24/8/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.6) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net | 9/6/2026 | 23/7/2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (8.4) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.1) | 0.68% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.8) | 0.42% | — | Kurt Software Studio Writeup Mobile APPAI | 4/6/2026 | 22/7/2026 | Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WriteUp Mobile App: from 1.3.0 through 04062026. | |
| Aplazada | Alta (7.5) | 0.30% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Pendiente de análisis | Crítica (9.8) | 0.81% | — | Catia Magic Collaboration StudioAI3DS Teamwork CloudAI | 1/6/2026 | 22/7/2026 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA Magic Release 2022x through CATIA Magic Release 2026x could lead to an unauthenticated remote code execution. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Whitestudio Easy Form BuilderAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy Form Builder easy-form-builder allows Blind SQL Injection.This issue affects Easy Form Builder: from n/a through <= 4.0.6. | |
| Aplazada | Media (6.1) | 0.64% | 💥 Exploit | Jegstudio GutenverseAI | 27/5/2026 | 17/6/2026 | The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` outputs the value of… | |
| Aplazada | Alta (7.1) | 0.23% | — | Thedaylightstudio Fuel CMSAI | 16/5/2026 | 17/6/2026 | Fuel CMS 1.4.13 contains a blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'col' parameter in the Activity Log interface. Attackers can send requests to the logs endpoint with malicious SQL payloads in the 'col' parameter to extract… | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Baja (3.3) | 0.50% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5) | 0.71% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 12/5/2026 | 10/8/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (4.3) | 0.64% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 12/5/2026 | 18/6/2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 5/5/2026 | 17/6/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.5.3 via the import_images() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 5/5/2026 | 17/6/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'separatorIconSVG' parameter in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.4) | 0.29% | — | Thedaylightstudio Fuel CMSAI | 28/4/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code. |