Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Bigsweetpotatostudio HyperchatAI | 28/4/2026 | 24/7/2026 | A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack… | |
| Aplazada | Media (5.5) | 0.47% | — | Joecastrom Mcp-chat-studioAI | 27/4/2026 | 17/6/2026 | A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the… | |
| Aplazada | Media (4.3) | 0.63% | — | Daylight Studio FuelcmsAI | 27/4/2026 | 5/7/2026 | A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal. | |
| Analizada | Baja (2.1) | 0.50% | — | Coze Studio | 26/4/2026 | 17/6/2026 | A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initiated remotely. The… | |
| Modificada | Alta (7.1) | 0.32% | — | Thedaylightstudio Fuel CMS | 16/4/2026 | 5/7/2026 | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message. | |
| Modificada | Alta (8.3) | 0.73% | — | Thedaylightstudio Fuel CMS | 15/4/2026 | 5/7/2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule. | |
| Aplazada | Media (4.3) | 0.23% | — | Longwatchstudio MyrewardsAI | 15/4/2026 | 17/6/2026 | Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/4/2026 | 15/7/2026 | Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 2.1% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/4/2026 | 15/7/2026 | Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (6.5) | 0.33% | — | Redpixelstudios RPS Include ContentAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in redpixelstudios RPS Include Content rps-include-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RPS Include Content: from n/a through <= 1.2.2. | |
| Modificada | Alta (8.8) | 0.90% | — | Thedaylightstudio Fuel CMS | 7/4/2026 | 5/7/2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. | |
| Analizada | Alta (7.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users… | |
| Analizada | Alta (8.7) | 0.74% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and… | |
| Analizada | Alta (8.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,… | |
| Analizada | Alta (8.5) | 0.18% | — | Twitch Studio | 6/4/2026 | 26/9/2026 | Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and… | |
| Aplazada | Media (6.4) | 0.26% | — | Jegstudio GutenverseAI | 4/4/2026 | 24/7/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.9) | 0.16% | — | Hhdsoftware Device Monitoring Studio | 30/3/2026 | 17/6/2026 | Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters… | |
| Analizada | Media (6.9) | 0.21% | — | Valentina-db Studio | 30/3/2026 | 17/6/2026 | Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts. | |
| Modificada | Alta (7.7) | 0.34% | — | Thedaylightstudio Fuel CMS | 26/3/2026 | 5/7/2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component. | |
| Modificada | Crítica (9.1) | 0.44% | — | Thedaylightstudio Fuel CMS | 26/3/2026 | 5/7/2026 | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. | |
| Modificada | Crítica (9.8) | 0.78% | — | Thedaylightstudio DwooThedaylightstudio Fuel CMS | 26/3/2026 | 5/7/2026 | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | |
| Aplazada | Alta (8.6) | 0.53% | — | Whitebox-studio ScapeAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16. | |
| Aplazada | Alta (7.1) | 0.18% | — | Progressionstudios VayvoAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8. | |
| Pendiente de análisis | Crítica (9) | 0.32% | — | Pega Browser ExtensionAIPega Robot StudioAI | 23/3/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The… | |
| Analizada | Media (6.9) | 0.17% | — | Pixarra Blob Studio | 23/3/2026 | 17/6/2026 | Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to… |