Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.32% | — | Dotnetfoundation Piranha CMS | 26/9/2025 | 17/6/2026 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser. | |
| Analizada | Media (6.1) | 0.21% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these cases, the application… | |
| Analizada | Media (5.9) | 0.19% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection, affecting any unsuspecting user clicking such link. This issue has been patched in version 10.1.0. | |
| Analizada | Media (5.3) | 0.26% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload a file with Unicode… | |
| Analizada | Media (4.8) | 0.18% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0. | |
| Analizada | Crítica (9) | 0.49% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain… | |
| Analizada | Media (5.4) | 0.18% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 30/9/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the website and to any other… | |
| Analizada | Media (6.5) | 0.43% | — | Dnnsoftware Dotnetnuke | 22/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients… | |
| Analizada | Alta (8.6) | 36% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version… | |
| Analizada | Alta (8.8) | 0.35% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in… | |
| Analizada | Media (6.1) | 0.23% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has been patched in version… | |
| Analizada | Media (5.1) | 0.21% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issue has been patched… | |
| Analizada | Crítica (9.1) | 0.46% | — | Ingydotnet Yaml-libyaml | 1/6/2025 | 17/6/2026 | YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified | |
| Analizada | Media (6.1) | 0.28% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. | |
| Analizada | Media (6) | 0.23% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Version 9.13.9 fixes the issue. | |
| Analizada | Baja (2.4) | 0.24% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue. | |
| Aplazada | Alta (8.7) | 0.61% | — | Amazon ION DotnetAI | 21/4/2025 | 17/6/2026 | When reading binary Ion data through Amazon.IonDotnet using the RawBinaryReader class, Amazon.IonDotnet does not check the number of bytes read from the underlying stream while deserializing the binary format. If the Ion data is malformed or truncated, this triggers an infinite loop condition that could potentially… | |
| Analizada | Alta (7.5) | 0.39% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8. | |
| Analizada | Media (6.5) | 0.38% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8. | |
| Analizada | Alta (7.5) | 0.37% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent… | |
| Analizada | Media (4.3) | 0.29% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is… | |
| Analizada | Media (6.5) | 0.30% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic… | |
| Analizada | Alta (7.5) | 0.18% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's… | |
| Aplazada | Alta (7.3) | 0.33% | — | Philips Intellispace PortalAIMicrosoft DotnetAI | 7/4/2025 | 17/6/2026 | The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can… | |
| Aplazada | Alta (7.5) | 0.51% | — | Opentelemetry DotnetAI | 5/3/2025 | 17/6/2026 | OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still… |