Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.53% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is… | |
| Analizada | Baja (2.1) | 0.71% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.9) | 0.30% | — | Progress Telerik UI FOR Asp.net Ajax | 25/2/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering. | |
| Modificada | Crítica (9.9) | 66% | 💥 Exploit | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | |
| Aplazada | Alta (8.8) | 0.77% | — | Microsoft Asp.netAIMicrosoft Diasymreader.dllAI | 8/9/2025 | 17/6/2026 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that… | |
| Aplazada | Alta (8.1) | 0.60% | — | Microsoft Asp.netAI | 8/9/2025 | 17/6/2026 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. | |
| Aplazada | Alta (7) | 0.65% | — | Microsoft Asp.net CoreAI | 8/7/2025 | 17/6/2026 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry. | |
| Analizada | Alta (7.5) | 24% | — | Progress Telerik UI FOR Asp.net Ajax | 14/5/2025 | 17/6/2026 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. | |
| Aplazada | Media (4.7) | 0.10% | — | Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI | 9/4/2025 | 17/6/2026 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.… | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 8/4/2025 | 17/6/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7) | 1.0% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 11/3/2025 | 17/6/2026 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.1) | 0.63% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714. | |
| Aplazada | Alta (7.5) | 0.52% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734. | |
| Aplazada | Media (4.7) | 0.53% | — | Duende IdentityserverAIMicrosoft Asp.net CoreAI | 31/7/2024 | 17/6/2026 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party,… | |
| Modificada | Media (6.5) | 0.49% | — | Honeywell Masmobile Asp.net ServicesHoneywell Masmobile Classic | 16/3/2024 | 17/6/2026 | Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history. | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Media (6.1) | 0.46% | — | Aspnetzero Asp.net Zero | 26/12/2023 | 17/6/2026 | An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages. | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | ASP.NET Core Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft Visual Studio 2022Microsoft Asp.net Core | 14/11/2023 | 17/6/2026 | ASP.NET Core Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Alta (7.5) | 14% | ⚠ Explotación activa | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022Fedoraproject Fedora | 8/8/2023 | 10/8/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 1.9% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 8/8/2023 | 10/8/2026 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 1.2% | — | Devexpress Asp.net WEB Forms Controls | 18/10/2022 | 17/6/2026 | The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE:… | |
| Modificada | Alta (7.8) | 0.72% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022 | 15/12/2021 | 17/6/2026 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability |