Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Xml-rpc.net Project Xml-rpc.net | 18/12/2022 | 17/6/2026 | An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft .net Framework | 13/12/2022 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Media (5.8) | 0.80% | — | Microsoft .net FrameworkMicrosoft Nuget | 9/11/2022 | 10/8/2026 | .NET Framework Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 1.2% | — | Devexpress Asp.net WEB Forms Controls | 18/10/2022 | 17/6/2026 | The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE:… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dotpdn Paint.net | 12/10/2022 | 17/6/2026 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2). | |
| Modificada | Crítica (9.8) | 1.0% | — | Dotpdn Paint.net | 12/10/2022 | 17/6/2026 | dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2). | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 11/10/2022 | 17/6/2026 | NuGet Client Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 4.0% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 13/9/2022 | 17/6/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.8) | 1.6% | — | Microsoft .net Framework | 13/9/2022 | 17/6/2026 | .NET Framework Remote Code Execution Vulnerability | |
| Modificada | Media (4.8) | 0.55% | — | Blogengine.net | 2/9/2022 | 17/6/2026 | BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | |
| Modificada | Alta (7.5) | 1.3% | — | Opcfoundation UA .net Standard Stack | 23/8/2022 | 17/6/2026 | OPC UA .NET Standard Reference Server 1.04.368 allows a remote attacker to cause the application to access sensitive information. | |
| Modificada | Media (5.9) | 2.4% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell | 9/8/2022 | 17/6/2026 | .NET Spoofing Vulnerability | |
| Modificada | Alta (7.5) | 1.7% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 2.0% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 1.4% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation. | |
| Modificada | Alta (7.5) | 1.7% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials. | |
| Modificada | Alta (7.5) | 1.6% | — | Opcfoundation UA .net Standard Stack | 16/6/2022 | 17/6/2026 | An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message. | |
| Modificada | Media (5.5) | 5.6% | — | Microsoft Visual Studio 2022Microsoft .netMicrosoft .net CoreMicrosoft Nuget+2 | 15/6/2022 | 17/6/2026 | .NET and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Media (5.9) | 1.5% | — | Ssh.net Project Ssh.net | 31/5/2022 | 17/6/2026 | SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When… | |
| Modificada | Media (6.5) | 0.74% | — | Blogengine.net | 18/5/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server. | |
| Modificada | Crítica (9.1) | 2.7% | — | Blogengine.net | 13/5/2022 | 17/6/2026 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. | |
| Modificada | Media (5.5) | 3.2% | — | Microsoft .net Framework | 10/5/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 5.4% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 10/5/2022 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 5.7% | 💥 PoC | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 10/5/2022 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability |