Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.4) | 0.24% | — | Dnnsoftware Dotnetnuke | 23/5/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue. | |
| Analizada | Alta (7.5) | 0.39% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8. | |
| Analizada | Media (6.5) | 0.38% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8. | |
| Analizada | Alta (7.5) | 0.37% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent… | |
| Analizada | Media (4.3) | 0.29% | — | Dnnsoftware Dotnetnuke | 9/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is… | |
| Analizada | Media (6.5) | 0.30% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic… | |
| Analizada | Alta (7.5) | 0.18% | — | Dnnsoftware Dotnetnuke | 8/4/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's… | |
| Modificada | Media (5.4) | 0.43% | — | Dnnsoftware Dotnetnuke | 12/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file. | |
| Modificada | Media (4.9) | 1.3% | — | Dnnsoftware Dotnetnuke | 30/9/2022 | 17/6/2026 | Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. | |
| Modificada | Media (5.4) | 0.67% | — | Dnnsoftware Dotnetnuke | 20/7/2022 | 17/6/2026 | DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. | |
| Modificada | Alta (7.5) | 1.1% | — | Dnnsoftware Dotnetnuke | 2/6/2022 | 17/6/2026 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common… | |
| Modificada | Media (4.3) | 0.69% | — | Dnnsoftware Dotnetnuke | 6/4/2020 | 17/6/2026 | There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file… | |
| Modificada | Media (6.5) | 1.9% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. | |
| Modificada | Alta (8.8) | 2.4% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). | |
| Modificada | Media (5.4) | 0.88% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). | |
| Modificada | Media (6.1) | 6.2% | — | Dnnsoftware Dotnetnuke | 26/9/2019 | 17/6/2026 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.… | |
| Modificada | Alta (7.5) | 54% | — | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812. | |
| Analizada | Alta (7.5) | 74% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | |
| Modificada | Alta (7.5) | 47% | — | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | |
| Analizada | Alta (7.5) | 76% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | |
| Modificada | Media (6.1) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/3/2019 | 17/6/2026 | DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. | |
| Modificada | Alta (7.5) | 13% | — | Dnnsoftware Dotnetnuke | 3/7/2018 | 17/6/2026 | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources. | |
| Analizada | Alta (8.8) | 95% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 20/7/2017 | 17/6/2026 | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | |
| Modificada | Crítica (9.8) | 75% | — | Dnnsoftware Dotnetnuke | 6/2/2017 | 17/6/2026 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx. | |
| Modificada | Media (5.4) | 0.66% | — | Dnnsoftware Dotnetnuke | 31/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. |