Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 29% | — | Microsoft .net Framework | 13/9/2018 | 17/6/2026 | A remote code execution vulnerability exists when Microsoft .NET Framework processes untrusted input, aka ".NET Framework Remote Code Execution Vulnerability." This affects Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET… | |
| Modificada | Alta (7.5) | 6.6% | — | Microsoft .net CoreMicrosoft Asp.net CoreMicrosoft System.io.pipelines | 13/9/2018 | 17/6/2026 | A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. | |
| Modificada | Alta (7.5) | 9.0% | — | Microsoft .net Framework | 15/8/2018 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft .NET Framework that could allow an attacker to access information in multi-tenant environments, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET… | |
| Modificada | Alta (7.8) | 1.8% | — | Red-gate .net ReflectorRed-gate Smartassembly | 31/7/2018 | 17/6/2026 | Redgate .NET Reflector before 10.0.7.774 and SmartAssembly before 6.12.5 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific embedded resource file. | |
| Modificada | Media (5.5) | 0.75% | — | Microsoft .net FrameworkMicrosoft Powershell CoreMicrosoft .net CoreMicrosoft .net Framework Developer Pack+1 | 11/7/2018 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1,… | |
| Modificada | Alta (8.1) | 42% | 💥 PoC | Microsoft .net FrameworkMicrosoft Project ServerMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation+1 | 11/7/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework… | |
| Modificada | Alta (8.8) | 16% | — | Microsoft .net Framework | 11/7/2018 | 17/6/2026 | A Remote Code Execution vulnerability exists in .NET software when the software fails to check the source markup of a file, aka ".NET Framework Remote Code Execution Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 4.7.2. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft .net Framework | 11/7/2018 | 17/6/2026 | An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level, aka ".NET Framework Elevation of Privilege Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft… | |
| Modificada | Alta (7.5) | 10% | — | Microsoft Asp.net CoreMicrosoft Asp.net Model View ControllerMicrosoft Asp.net Webpages | 11/7/2018 | 17/6/2026 | A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2. | |
| Modificada | Alta (8.8) | 1.0% | — | Opcfoundation Ua-.net-legacy | 14/6/2018 | 17/6/2026 | Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code. | |
| Modificada | Media (5.3) | 1.2% | — | Opcfoundation Ua-.net-legacyOpcfoundation Ua-.netstandard | 13/6/2018 | 17/6/2026 | An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13. A vulnerability in OPC UA applications can allow a remote attacker to determine a Server's private key by sending carefully constructed… | |
| Modificada | Crítica (9.8) | 24% | 💥 Exploit | Cirt.net Nikto | 1/6/2018 | 17/6/2026 | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft .net Framework | 9/5/2018 | 17/6/2026 | A security feature bypass vulnerability exists in .Net Framework which could allow an attacker to bypass Device Guard, aka ".NET Framework Device Guard Security Feature Bypass Vulnerability." This affects Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET… | |
| Modificada | Alta (7.5) | 8.3% | — | Microsoft .net CoreMicrosoft .net Framework | 9/5/2018 | 17/6/2026 | A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1,… | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Sitecore.net | 27/4/2018 | 17/6/2026 | An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file=… | |
| Modificada | Media (6.1) | 0.67% | — | Catalooksupport .netstore | 16/4/2018 | 17/6/2026 | The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter. | |
| Modificada | Alta (7.5) | 9.1% | — | Microsoft Asp.net CoreMicrosoft Powershell Core | 14/3/2018 | 17/6/2026 | .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability". | |
| Modificada | Alta (7.5) | 7.8% | — | Microsoft Asp.net Core | 14/3/2018 | 17/6/2026 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0784. | |
| Modificada | Alta (8.8) | 9.6% | — | Microsoft Asp.net Core | 14/3/2018 | 17/6/2026 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability". | |
| Modificada | Alta (8.8) | 0.50% | — | Beims Contractorweb.net | 15/1/2018 | 17/6/2026 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire… | |
| Modificada | Crítica (9.8) | 1.3% | — | Beims Contractorweb.net | 15/1/2018 | 17/6/2026 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details. | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability." | |
| Modificada | Media (6.5) | 3.0% | — | Microsoft Asp.net Core | 10/1/2018 | 17/6/2026 | ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability". | |
| Modificada | Alta (8.8) | 6.5% | — | Microsoft Asp.net Core | 10/1/2018 | 17/6/2026 | ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808. | |
| Modificada | Alta (7.5) | 8.9% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765. |