Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1416 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.47%—Bigsweetpotatostudio HyperchatAI28/4/202624/7/2026
A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2.0.0-alpha.63. Affected by this issue is the function fetch of the file packages/core/src/http/aiProxyMiddleware.mts of the component AI Proxy Middleware. Such manipulation of the argument baseurl leads to server-side request forgery. The attack…
AplazadaMedia (5.5)0.47%—Joecastrom Mcp-chat-studioAI27/4/202617/6/2026
A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1.5.0. Affected by this issue is some unknown functionality of the file server/routes/llm.js of the component LLM Models API. Performing a manipulation of the argument req.query.base_url results in server-side request forgery. Remote exploitation of the…
AplazadaMedia (4.3)0.63%—Daylight Studio FuelcmsAI27/4/20265/7/2026
A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.
AnalizadaBaja (2.1)0.50%—Coze Studio26/4/202617/6/2026
A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component databaseTool. Performing a manipulation results in sql injection. The attack can be initiated remotely. The…
ModificadaAlta (7.1)0.32%—Thedaylightstudio Fuel CMS16/4/20265/7/2026
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.
ModificadaAlta (8.3)0.73%—Thedaylightstudio Fuel CMS15/4/20265/7/2026
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.
AplazadaMedia (4.3)0.23%—Longwatchstudio MyrewardsAI15/4/202617/6/2026
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.
ModificadaAlta (7.5)2.4%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/4/202615/7/2026
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)2.1%—Microsoft .netMicrosoft Visual Studio 202214/4/202615/7/2026
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (6.5)0.33%—Redpixelstudios RPS Include ContentAI8/4/202624/7/2026
Missing Authorization vulnerability in redpixelstudios RPS Include Content rps-include-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RPS Include Content: from n/a through <= 1.2.2.
ModificadaAlta (8.8)0.90%—Thedaylightstudio Fuel CMS7/4/20265/7/2026
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
AnalizadaAlta (7.7)0.98%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users…
AnalizadaAlta (8.7)0.74%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and…
AnalizadaAlta (8.7)0.98%—Amazon Research AND Engineering Studio6/4/202624/7/2026
Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,…
AnalizadaAlta (8.5)0.18%—Twitch Studio6/4/202626/9/2026
Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and…
AplazadaMedia (6.4)0.26%—Jegstudio GutenverseAI4/4/202624/7/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.9)0.16%—Hhdsoftware Device Monitoring Studio30/3/202617/6/2026
Device Monitoring Studio 8.10.00.8925 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the server connection dialog. Attackers can trigger the crash by entering a malformed server name or address containing repeated characters…
AnalizadaMedia (6.9)0.21%—Valentina-db Studio30/3/202617/6/2026
Valentina Studio 9.0.4 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Host field. Attackers can trigger the crash by pasting a 256-byte buffer of repeated characters into the Host parameter during server connection attempts.
ModificadaAlta (7.7)0.34%—Thedaylightstudio Fuel CMS26/3/20265/7/2026
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
ModificadaCrítica (9.1)0.44%—Thedaylightstudio Fuel CMS26/3/20265/7/2026
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
ModificadaCrítica (9.8)0.78%—Thedaylightstudio DwooThedaylightstudio Fuel CMS26/3/20265/7/2026
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
AplazadaAlta (8.6)0.53%—Whitebox-studio ScapeAI25/3/202617/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal.This issue affects Scape: from n/a through < 1.5.16.
AplazadaAlta (7.1)0.18%—Progressionstudios VayvoAI25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8.
Pendiente de análisisCrítica (9)0.32%—Pega Browser ExtensionAIPega Robot StudioAI23/3/202617/6/2026
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The…
AnalizadaMedia (6.9)0.17%—Pixarra Blob Studio23/3/202617/6/2026
Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to…