Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Zuuse Beims Contractorweb .net | 18/12/2017 | 17/6/2026 | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter. | |
| Modificada | Alta (7.5) | 10% | — | Microsoft Asp.net Core | 15/11/2017 | 17/6/2026 | ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". | |
| Modificada | Alta (8.8) | 9.4% | — | Microsoft Asp.net Core | 15/11/2017 | 17/6/2026 | ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability". | |
| Modificada | Crítica (9.8) | 2.6% | — | Recurly Client .net | 13/11/2017 | 17/6/2026 | The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources. | |
| Modificada | Media (6.1) | 1.4% | — | Popcash.net Code Integration Tool | 23/10/2017 | 17/6/2026 | The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php. | |
| Analizada | Alta (7.8) | 89% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 13/9/2017 | 17/6/2026 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." | |
| Modificada | Alta (8.2) | 2.9% | — | Siemens Simatic Pcs7Siemens WinccOcpfoundation Local Discovery ServerOcpfoundation UA .net | 30/8/2017 | 17/6/2026 | An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All… | |
| Analizada | Crítica (9.8) | 78% | ⚠ Explotación activa💥 Exploit | Progress Telerik UI FOR Asp.net Ajax | 23/8/2017 | 14/8/2026 | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Telerik UI FOR Asp.net Ajax | 23/8/2017 | 17/6/2026 | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |
| Modificada | Alta (7.5) | 9.5% | — | Microsoft .net Framework | 11/7/2017 | 17/6/2026 | Microsoft .NET Framework 4.6, 4.6.1, 4.6.2, and 4.7 allow an attacker to send specially crafted requests to a .NET web application, resulting in denial of service, aka .NET Denial of Service Vulnerability. | |
| Analizada | Crítica (9.8) | 75% | ⚠ Explotación activa💥 Exploit | Progress SitefinityTelerik UI FOR Asp.net Ajax | 3/7/2017 | 17/6/2026 | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey… | |
| Modificada | Media (6.1) | 0.78% | — | Sitecore.net | 23/6/2017 | 17/6/2026 | Sitecore.NET 7.1 through 7.2 has a Cross Site Scripting Vulnerability via the searchStr parameter to the /Search-Results URI. | |
| Modificada | Crítica (9.8) | 2.7% | — | Ideablade Breeze.server.net | 22/6/2017 | 17/6/2026 | IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization. | |
| Modificada | Crítica (9.8) | 1.2% | — | Newrelic .net Agent | 13/6/2017 | 17/6/2026 | New Relic .NET Agent before 6.3.123.0 adds SQL injection flaws to safe applications via vectors involving failure to escape quotes during use of the Slow Queries feature, as demonstrated by a mishandled quote in a VALUES clause of an INSERT statement, after bypassing a SET SHOWPLAN_ALL ON protection mechanism. | |
| Modificada | Media (5.3) | 3.5% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.3) | 4.2% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. | |
| Modificada | Alta (7.5) | 5.5% | 💥 PoC | Microsoft .net Framework | 12/5/2017 | 17/6/2026 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." | |
| Modificada | Alta (7.5) | 17% | — | Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+14 | 12/5/2017 | 17/6/2026 | A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3… | |
| Modificada | Media (6.6) | 5.0% | 💥 Exploit | Mor-pah.net Dmitry Deepmagic Information Gathering Tool | 20/4/2017 | 17/6/2026 | Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local… | |
| Modificada | Crítica (9.1) | 1.5% | — | Grabacr.net Kancolleviewer | 13/4/2017 | 17/6/2026 | KanColleViewer versions 3.8.1 and earlier operates as an open proxy which allows remote attackers to trigger outbound network traffic. | |
| Modificada | Alta (7.8) | 18% | 💥 Exploit | Microsoft .net Framework | 12/4/2017 | 17/6/2026 | Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." | |
| Modificada | Alta (7.5) | 20% | — | Microsoft .net Framework | 20/12/2016 | 17/6/2026 | The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mechanism and obtain sensitive cleartext information by leveraging key guessability, aka ".NET Information Disclosure Vulnerability." | |
| Modificada | Media (5.5) | 54% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Office+10 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010;… | |
| Modificada | Alta (7.5) | 25% | — | Microsoft .net Framework | 13/7/2016 | 17/6/2026 | Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability." | |
| Modificada | Media (5.9) | 8.4% | — | Microsoft .net Framework | 11/5/2016 | 17/6/2026 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext information via vectors involving injection of cleartext data into the client-server data stream, aka "TLS/SSL Information Disclosure Vulnerability." |