Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 1.0% | — | Opcfoundation Netstandard.opc.uaOpcfoundation Ua-.netstandard | 16/3/2020 | 17/6/2026 | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network. | |
| Modificada | Crítica (9.8) | 6.1% | — | Apereo .net CAS ClientApereo Java CAS ClientApereo PhpcasDebian Linux+1 | 24/1/2020 | 17/6/2026 | A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | |
| Modificada | Alta (8.8) | 17% | — | Microsoft .net FrameworkMicrosoft .net Core | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is… | |
| Modificada | Alta (8.8) | 18% | — | Microsoft .net FrameworkMicrosoft .net Core | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is… | |
| Modificada | Alta (8.8) | 21% | — | Microsoft Asp.net CoreRedhat Enterprise LinuxRedhat Enterprise Linux EUS | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 7.6% | — | Microsoft Asp.net CoreRedhat Enterprise LinuxRedhat Enterprise Linux EUS | 14/1/2020 | 17/6/2026 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | |
| Modificada | Crítica (9.8) | 3.0% | — | Progress Telerik UI FOR Asp.net AjaxTelerik Radchart | 13/12/2019 | 17/6/2026 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Telerik UI FOR Asp.net Ajax | 11/12/2019 | 17/6/2026 | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of… | |
| Modificada | Media (5.4) | 0.65% | — | Jitbit .net Forum | 1/11/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Jitbit .NET Forum (aka ASP.NET forum) 8.3.8 allows remote attackers to inject arbitrary web script or HTML via the gravatar URL parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+34 | 31/10/2019 | 17/6/2026 | plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes. | |
| Modificada | Alta (7.5) | 0.89% | — | Auth0.net | 8/10/2019 | 17/6/2026 | Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to validate untrusted ID tokens. | |
| Modificada | Alta (8.8) | 4.8% | — | Microsoft Asp.net Core | 11/9/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'. | |
| Modificada | Alta (7.5) | 5.3% | — | Microsoft .net CoreMicrosoft Powershell Core | 11/9/2019 | 17/6/2026 | A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. | |
| Modificada | Media (5.5) | 1.0% | — | Microsoft .net Framework | 11/9/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. | |
| Modificada | Media (6.1) | 0.95% | — | Ithemes Authorize.net | 28/8/2019 | 17/6/2026 | Authorize.net Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | |
| Modificada | Alta (8.8) | 10.0% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2017 | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 7.8% | 💥 PoC | Microsoft .net Framework | 15/7/2019 | 17/6/2026 | A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'. | |
| Modificada | Media (6.1) | 2.6% | — | Microsoft Asp.net Core | 15/7/2019 | 17/6/2026 | A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. | |
| Modificada | Alta (7.5) | 6.0% | 💥 PoC | Microsoft .net FrameworkMicrosoft IdentitymodelMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation+9 | 15/7/2019 | 17/6/2026 | An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. | |
| Modificada | Crítica (9.8) | 5.7% | — | Sun.net Wmpro | 11/7/2019 | 17/6/2026 | The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication. | |
| Modificada | Media (6.1) | 0.97% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx. | |
| Modificada | Alta (7.1) | 5.4% | 💥 Exploit | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | |
| Modificada | Alta (8.8) | 7.1% | — | Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. |