Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1417 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.17% | — | Pixarra Blob Studio | 23/3/2026 | 17/6/2026 | Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of repeated characters and trigger the application to read it, causing the application to… | |
| Analizada | Media (6.9) | 0.17% | — | Pixarra Liquid Studio | 23/3/2026 | 17/6/2026 | Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Luminance Studio | 23/3/2026 | 17/6/2026 | Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the… | |
| Analizada | Media (6.9) | 0.17% | — | Pixarra Paint Studio | 23/3/2026 | 17/6/2026 | Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the application to crash and… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Pixel Studio | 23/3/2026 | 17/6/2026 | Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or terminate abnormally. | |
| Analizada | Media (6.9) | 0.17% | — | Pixarra Tree Studio | 23/3/2026 | 17/6/2026 | Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become… | |
| Analizada | Media (6.9) | 0.18% | — | Valentina-db Studio | 21/3/2026 | 17/6/2026 | Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field… | |
| Analizada | Media (6.9) | 0.19% | — | Pixarra Selfie Studio | 21/3/2026 | 17/6/2026 | Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a large string of characters into the New Width or New Height field to trigger a buffer overflow that crashes the… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application… | |
| Analizada | Media (6.9) | 0.19% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the… | |
| Analizada | Media (6.9) | 0.18% | — | Pixarra Twistedbrush PRO Studio | 21/3/2026 | 17/6/2026 | TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder… | |
| Aplazada | Alta (7.1) | 0.20% | — | Artstudioworks BrooksideAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.This issue affects Brookside: from n/a through 1.4. | |
| Analizada | Baja (2.7) | 0.38% | — | Studiocms | 18/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `getUsers` endpoint in StudioCMS uses the attacker-controlled `rank` query parameter to decide whether owner accounts should be filtered from the result set. As a result, an admin token can request… | |
| Aplazada | Media (5.3) | 0.26% | — | Studio99 WP MonitorAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Studio99 Studio99 WP Monitor studio99-wp-monitor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Studio99 WP Monitor: from n/a through <= 1.0.3. | |
| Analizada | Alta (7.2) | 0.36% | — | Studiocms | 11/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API createUser endpoint uses string-based rank checks that only block creating owner accounts, while the Dashboard API uses indexOf-based rank comparison that prevents creating users at or above your own… | |
| Analizada | Media (5.4) | 0.30% | — | Studiocms | 11/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNotifications endpoint accepts a user ID from the request payload and uses it to update that user's notification preferences. It checks that the caller is logged in but never verifies that the caller… | |
| Analizada | Alta (7.2) | 0.43% | — | Studiocms | 11/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password reset token for any other user, including the owner account. The handler… | |
| Analizada | Media (6.3) | 0.28% | — | Studiocms | 11/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage manager's isAuthorized() function is declared async (returns Promise<boolean>) but is called without await in both the POST and PUT handlers. Since a Promise object is always truthy in JavaScript,… | |
| Analizada | Alta (7.1) | 0.46% | 💥 PoC | Studiocms | 10/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user, including admin and owner accounts. The handler… | |
| Analizada | Alta (8.8) | 0.56% | 💥 PoC | Studiocms | 10/3/2026 | 17/6/2026 | StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint fails to validate whether… | |
| Aplazada | Crítica (10) | 0.45% | — | Microsoft Visual Studio CodeAIAquasec TrivyAI | 5/3/2026 | 17/6/2026 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users… | |
| Aplazada | Alta (7.1) | 0.26% | — | Janstudio ClaueAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JanStudio Claue - Clean, Minimal Elementor WooCommerce Theme claue allows Reflected XSS.This issue affects Claue - Clean, Minimal Elementor WooCommerce Theme: from n/a through <= 2.2.7. | |
| Analizada | Crítica (9.3) | 0.56% | — | Studiofabryka Dorbycms | 2/3/2026 | 17/6/2026 | DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution. This issue was fixed in versions above 5.0. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpdevstudio Easy Taxonomy ImagesAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevstudio Easy Taxonomy Images easy-taxonomy-images allows Stored XSS.This issue affects Easy Taxonomy Images: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Whitestudio Easy Form BuilderAI | 14/2/2026 | 17/6/2026 | The Easy Form Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX actions in all versions up to, and including, 3.9.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve sensitive form response… |