Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 31% | 💥 Exploit | Blogengine.net | 21/6/2023 | 17/6/2026 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | |
| Modificada | Alta (7.5) | 2.2% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 0.90% | — | Microsoft .net Framework | 14/6/2023 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.6% | — | Microsoft .net FrameworkMicrosoft .net | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual StudioMicrosoft Visual Studio 2017+2 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 1.00% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.60% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/6/2023 | 17/6/2026 | .NET and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 1.2% | — | Sun.net Ehrd Ctms | 27/4/2023 | 17/6/2026 | SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to perform arbitrary system operation or disrupt service. | |
| Modificada | Alta (7.8) | 1.5% | — | Microsoft .netMicrosoft Visual Studio 2022 | 11/4/2023 | 17/6/2026 | .NET DLL Hijacking Remote Code Execution Vulnerability | |
| Modificada | Media (5.3) | 0.43% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs. | |
| Modificada | Media (5.4) | 0.36% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post. | |
| Modificada | Media (5.4) | 0.38% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.9% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 14/2/2023 | 19/8/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5) | 0.92% | — | Microsoft .net Framework | 14/2/2023 | 19/8/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Media (5.4) | 0.67% | — | Yetanotherforum Yaf.net | 2/2/2023 | 17/6/2026 | A vulnerability was found in YAFNET up to 3.1.11 and classified as problematic. This issue affects some unknown processing of the component Signature Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Media (5.4) | 0.69% | — | Yetanotherforum Yaf.net | 27/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in YAFNET up to 3.1.10. This issue affects some unknown processing of the file /forum/PostPrivateMessage of the component Private Message Handler. The manipulation of the argument subject/message leads to cross site scripting. The attack may be… | |
| Modificada | Crítica (9.8) | 0.76% | — | Blogengine.net | 18/1/2023 | 17/6/2026 | BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft .netMicrosoft PowershellFedoraproject Fedora | 10/1/2023 | 17/6/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.2) | 1.2% | — | Blogengine.net | 19/12/2022 | 17/6/2026 | An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. |