Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

758 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.47%—Microsoft .net11/8/20263/9/2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.35%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.
AnalizadaMedia (5.3)0.43%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
AnalizadaMedia (6.5)0.42%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication…
AnalizadaAlta (8.1)0.50%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
AnalizadaAlta (7.5)0.36%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
AnalizadaMedia (5.9)0.16%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
AnalizadaAlta (8.1)0.34%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
AnalizadaAlta (8.1)0.73%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
AnalizadaAlta (8.1)0.67%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
AnalizadaAlta (7.5)0.27%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit…
AnalizadaAlta (7.5)0.45%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
AnalizadaAlta (7.5)0.50%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
AnalizadaAlta (8.1)0.74%💥 PoCProgress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
AnalizadaMedia (6.5)0.74%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)0.46%—Microsoft .net FrameworkMicrosoft .net14/7/202624/7/2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)4.0%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202614/7/202624/7/2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)4.0%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.2)0.61%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.5)0.22%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.