Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.4)1.0%—Opcfoundation Netstandard.opc.uaOpcfoundation Ua-.netstandard16/3/202017/6/2026
In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.
ModificadaCrítica (9.8)6.1%—Apereo .net CAS ClientApereo Java CAS ClientApereo PhpcasDebian Linux+124/1/202017/6/2026
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitMicrosoft .net Framework14/1/202017/6/2026
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
ModificadaAlta (8.8)17%—Microsoft .net FrameworkMicrosoft .net Core14/1/202017/6/2026
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is…
ModificadaAlta (8.8)18%—Microsoft .net FrameworkMicrosoft .net Core14/1/202017/6/2026
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is…
ModificadaAlta (8.8)21%—Microsoft Asp.net CoreRedhat Enterprise LinuxRedhat Enterprise Linux EUS14/1/202017/6/2026
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)7.6%—Microsoft Asp.net CoreRedhat Enterprise LinuxRedhat Enterprise Linux EUS14/1/202017/6/2026
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ModificadaCrítica (9.8)3.0%—Progress Telerik UI FOR Asp.net AjaxTelerik Radchart13/12/201917/6/2026
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitTelerik UI FOR Asp.net Ajax11/12/201917/6/2026
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of…
ModificadaMedia (5.4)0.65%—Jitbit .net Forum1/11/201917/6/2026
A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter.
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaAlta (7.5)0.89%—Auth0.net8/10/201917/6/2026
Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens.
ModificadaAlta (8.8)4.8%—Microsoft Asp.net Core11/9/201917/6/2026
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.
ModificadaAlta (7.5)5.3%—Microsoft .net CoreMicrosoft Powershell Core11/9/201917/6/2026
A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.
ModificadaMedia (5.5)1.0%—Microsoft .net Framework11/9/201917/6/2026
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
ModificadaMedia (6.1)0.95%—Ithemes Authorize.net28/8/201917/6/2026
Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaAlta (8.8)10.0%—Microsoft .net FrameworkMicrosoft Visual Studio 201715/7/201917/6/2026
A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)7.8%💥 PoCMicrosoft .net Framework15/7/201917/6/2026
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
ModificadaMedia (6.1)2.6%—Microsoft Asp.net Core15/7/201917/6/2026
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
ModificadaAlta (7.5)6.0%💥 PoCMicrosoft .net FrameworkMicrosoft IdentitymodelMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation+915/7/201917/6/2026
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
ModificadaCrítica (9.8)5.7%—Sun.net Wmpro11/7/201917/6/2026
The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
ModificadaMedia (6.1)0.97%—Dotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
ModificadaAlta (7.1)5.4%💥 ExploitDotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
ModificadaAlta (7.5)1.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
ModificadaAlta (8.8)7.1%—Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.