Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.53%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is…
AnalizadaBaja (2.1)0.71%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.9)0.30%—Progress Telerik UI FOR Asp.net Ajax25/2/202617/6/2026
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
ModificadaCrítica (9.9)66%💥 ExploitMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/10/202517/6/2026
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
AplazadaAlta (8.8)0.77%—Microsoft Asp.netAIMicrosoft Diasymreader.dllAI8/9/202517/6/2026
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that…
AplazadaAlta (8.1)0.60%—Microsoft Asp.netAI8/9/202517/6/2026
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution.
AplazadaAlta (7)0.65%—Microsoft Asp.net CoreAI8/7/202517/6/2026
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
AnalizadaAlta (7.5)24%—Progress Telerik UI FOR Asp.net Ajax14/5/202517/6/2026
In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
AplazadaMedia (4.7)0.10%—Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI9/4/202517/6/2026
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.…
AnalizadaAlta (7.5)1.7%—Microsoft Asp.net CoreMicrosoft Visual Studio 20228/4/202517/6/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7)1.0%—Microsoft Asp.net CoreMicrosoft Visual Studio 202211/3/202517/6/2026
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.1)0.63%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.
AplazadaAlta (7.5)0.52%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.
AplazadaMedia (4.7)0.53%—Duende IdentityserverAIMicrosoft Asp.net CoreAI31/7/202417/6/2026
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party,…
ModificadaMedia (6.5)0.49%—Honeywell Masmobile Asp.net ServicesHoneywell Masmobile Classic16/3/202417/6/2026
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
ModificadaAlta (7.5)2.7%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.5)2.4%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaMedia (6.1)0.46%—Aspnetzero Asp.net Zero26/12/202317/6/2026
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
ModificadaMedia (5.5)1.1%—Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/11/202317/6/2026
ASP.NET Core Security Feature Bypass Vulnerability
ModificadaAlta (7.5)2.8%—Microsoft Visual Studio 2022Microsoft Asp.net Core14/11/202317/6/2026
ASP.NET Core Denial of Service Vulnerability
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
AnalizadaAlta (7.5)14%⚠ Explotación activaMicrosoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022Fedoraproject Fedora8/8/202310/8/2026
.NET and Visual Studio Denial of Service Vulnerability
ModificadaAlta (7.5)1.9%—Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 20228/8/202310/8/2026
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
ModificadaAlta (7.5)1.2%—Devexpress Asp.net WEB Forms Controls18/10/202217/6/2026
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE:…
ModificadaAlta (7.8)0.72%—Microsoft Asp.net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 202215/12/202117/6/2026
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
Orbitaley — Vulnerabilidades