Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)7.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.
ModificadaAlta (7.5)2.7%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
ModificadaAlta (7.5)6.7%—Microsoft Asp.net Core16/5/201917/6/2026
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ModificadaAlta (7.5)4.9%—Microsoft .net CoreMicrosoft .net Framework16/5/201917/6/2026
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
ModificadaAlta (7.5)4.9%—Microsoft .net CoreMicrosoft .net Framework16/5/201917/6/2026
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.
ModificadaMedia (5.5)1.4%—Microsoft .net Framework16/5/201917/6/2026
A denial of service vulnerability exists when .NET Framework improperly handles objects in heap memory, aka '.NET Framework Denial of Service Vulnerability'.
ModificadaAlta (7.5)5.7%—Microsoft .net CoreMicrosoft .net FrameworkRedhat Enterprise LinuxRedhat Enterprise Linux EUS+216/5/201917/6/2026
A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.
ModificadaMedia (6.5)5.5%—Rapidflows Rapid4Microsoft .net Framework14/5/201917/6/2026
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
ModificadaCrítica (9.8)16%💥 ExploitBlogengine.net7/5/201917/6/2026
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
ModificadaAlta (7.5)7.0%—Microsoft Asp.net Core9/4/201917/6/2026
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
ModificadaMedia (6.5)2.7%—Microsoft Visual Studio 2017Microsoft NugetMono-project Mono FrameworkMicrosoft .net Core SDK+49/4/201917/6/2026
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
ModificadaCrítica (9.8)32%💥 ExploitBlogengine.net21/3/201917/6/2026
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user…
ModificadaMedia (5.9)4.5%—Microsoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017Microsoft .net Framework5/3/201917/6/2026
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.
ModificadaAlta (8.8)15%—Microsoft .net FrameworkMicrosoft Visual Studio 20175/3/201917/6/2026
A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework and Visual Studio Remote Code…
ModificadaAlta (7.5)8.4%—Microsoft Asp.net Core8/1/201917/6/2026
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.
ModificadaAlta (7.5)8.2%—Microsoft Asp.net Core8/1/201917/6/2026
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.
ModificadaAlta (7.5)9.6%—Microsoft .net FrameworkMicrosoft .net Core8/1/201917/6/2026
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework…
ModificadaCrítica (9.8)22%—Microsoft .net Framework12/12/201817/6/2026
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework…
ModificadaAlta (7.5)5.7%—Microsoft .net Framework12/12/201817/6/2026
A denial of service vulnerability exists when .NET Framework improperly handles special web requests, aka ".NET Framework Denial Of Service Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework…
ModificadaMedia (6.5)7.3%—Microsoft Asp.net Core14/11/201817/6/2026
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
ModificadaAlta (7.5)15%—Microsoft Asp.net CoreMicrosoft Powershell Core10/10/201817/6/2026
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
ModificadaMedia (5.3)1.0%—Progress Telerik Extensions FOR Asp.net MVC8/10/201817/6/2026
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
ModificadaMedia (5.3)0.29%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard3/10/201817/6/2026
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.
ModificadaAlta (8.2)1.6%—Opcfoundation Ua-.net-legacyOpcfoundation Ua-java14/9/201817/6/2026
An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.
ModificadaAlta (7.5)12%💥 PoCOpcfoundation Unified Architecture-.net-legacyOpcfoundation Unified Architecture-javaOpcfoundation Unified Architecture .net-standardOpcfoundation Unified Architecture Ansic+114/9/201817/6/2026
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.