Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | — | — | Bugtracker.netAI | 7/10/2026 | 7/10/2026 | Path traversal vulnerability in the BugTracker.NET file download component. The parameter used to specify the file name does not properly validate user-supplied paths. An authenticated remote attacker could enter a manipulated path to access files located outside the intended directory. Successful exploitation could… | |
| Aplazada | Alta (7.5) | — | — | Bugtracker.netAI | 7/10/2026 | 7/10/2026 | Unrestricted file upload vulnerability in the BugTracker.NET attachment functionality. An authenticated user with administrator privileges could modify the application configuration to store files in a directory accessible via the web interface. Due to the lack of proper file extension validation, an attacker could… | |
| Aplazada | Alta (7.5) | — | — | Bugtracker.netAI | 7/10/2026 | 7/10/2026 | Operating system command injection vulnerability in the SVN integration component of BugTracker.NET. The application incorporates the value of the field corresponding to the repository into an svn.exe command without properly validating it. An authenticated user with administrator privileges could store manipulated… | |
| Aplazada | Media (5.1) | 0.20% | — | Digiwin Easyflow .netAI | 30/9/2026 | 30/9/2026 | EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Pendiente de análisis | Media (6.5) | 0.29% | — | Io.netty Netty-codec-memcacheAI | 18/9/2026 | 25/9/2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can… | |
| Aplazada | Media (6.1) | 0.27% | 💥 PoC | Cutesoft Components Cute Editor FOR Asp.netAI | 17/9/2026 | 22/9/2026 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component,… | |
| Pendiente de análisis | Alta (7.5) | 0.62% | — | Ssh.netAI | 16/9/2026 | 30/9/2026 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an… | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.76% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.84% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.9) | 0.88% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 30/9/2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.27% | — | Microsoft .netMicrosoft .net SDKMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 7/10/2026 | Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core Odata | 8/9/2026 | 5/10/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Pendiente de análisis | Alta (7.1) | 0.42% | — | Ssh.netAI | 18/8/2026 | 18/9/2026 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious,… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 11/8/2026 | 17/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 8/9/2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. |