Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.7% | — | Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+2 | 10/5/2022 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (6.5) | 2.4% | — | Microsoft Azure SDK FOR .net | 15/4/2022 | 17/6/2026 | Azure SDK for .NET Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 3.6% | — | Microsoft .net Framework | 15/4/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Media (6.3) | 1.6% | — | Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+2 | 9/3/2022 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 3.6% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 9/3/2022 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft .netMicrosoft Visual Studio 2019Microsoft Visual Studio 2022Fedoraproject Fedora | 9/2/2022 | 17/6/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 2.1% | — | Classapps Selectsurvey.net | 28/1/2022 | 17/6/2026 | SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection. | |
| Modificada | Alta (7.5) | 2.0% | — | Classapps Selectsurvey.net | 28/1/2022 | 17/6/2026 | A file disclosure vulnerability in the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve survey user submitted data by modifying the value of the ID parameter in sequential order beginning from 1. | |
| Modificada | Alta (7.5) | 3.1% | — | Microsoft .net Framework | 11/1/2022 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Media (5.4) | 0.82% | — | Ajax.net Professional Project Ajax.net Professional | 22/12/2021 | 17/6/2026 | Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json… | |
| Modificada | Alta (7.8) | 0.72% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022 | 15/12/2021 | 17/6/2026 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 83% | ⚠ Explotación activa💥 Exploit | Ajaxpro.2 Project Ajaxpro.2Michaelschwarz Ajax.net Professional | 3/12/2021 | 27/8/2026 | All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution. | |
| Modificada | Media (5.7) | 20% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2019 | 13/10/2021 | 17/6/2026 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Media (6.1) | 2.0% | — | Datatables.net | 27/9/2021 | 17/6/2026 | This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped. | |
| Modificada | Crítica (9.8) | 1.7% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal | |
| Modificada | Crítica (9.8) | 1.4% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation. | |
| Modificada | Alta (7.8) | 0.23% | — | Cisco Appdynamics .net Agent | 18/8/2021 | 17/6/2026 | A vulnerability in the AppDynamics .NET Agent for Windows could allow an attacker to leverage an authenticated, local user account to gain SYSTEM privileges. This vulnerability is due to the .NET Agent Coordinator Service executing code with SYSTEM privileges. An attacker with local access to a device that is running… | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2019 | 12/8/2021 | 10/8/2026 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 3.9% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 12/8/2021 | 10/8/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (5.5) | 1.5% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 12/8/2021 | 7/10/2026 | .NET Core and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 0.57% | — | Microsoft .net Education Bundle SDK Install ToolMicrosoft .net Install Tool FOR Extension Authors | 14/7/2021 | 10/8/2026 | Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.0% | — | Elfinder.net.core Project Elfinder.net.core | 14/7/2021 | 17/6/2026 | This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Nica Winwaste.net | 8/7/2021 | 9/7/2026 | WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges. | |
| Modificada | Alta (7.8) | 0.32% | — | Blizzard Battle.net | 9/6/2021 | 17/6/2026 | Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which… | |
| Modificada | Alta (7.5) | 5.1% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Fedoraproject Fedora | 8/6/2021 | 7/10/2026 | ASP.NET Core Denial of Service Vulnerability |