Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.4)0.24%—Dnnsoftware Dotnetnuke23/5/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, a malicious SuperUser (Host) could craft a request to use an external url for a site export to then be imported. Version 9.13.9 fixes the issue.
AnalizadaAlta (7.5)0.39%—Dnnsoftware Dotnetnuke9/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.
AnalizadaMedia (6.5)0.38%—Dnnsoftware Dotnetnuke9/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is fixed in 9.13.8.
AnalizadaAlta (7.5)0.37%—Dnnsoftware Dotnetnuke9/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent…
AnalizadaMedia (4.3)0.29%—Dnnsoftware Dotnetnuke9/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A url could be crafted to the DNN ImageHandler to render text from a querystring parameter. This text would display in the resulting image and a user that trusts the domain might think that the information is…
AnalizadaMedia (6.5)0.30%—Dnnsoftware Dotnetnuke8/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. The algorithm used to generate the captcha image shows the least complexity of the desired image. For this reason, the created image can be easily read by OCR tools, and the intruder can send automatic…
AnalizadaAlta (7.5)0.18%—Dnnsoftware Dotnetnuke8/4/202517/6/2026
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's…
ModificadaMedia (5.4)0.43%—Dnnsoftware Dotnetnuke12/4/202317/6/2026
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
ModificadaMedia (4.9)1.3%—Dnnsoftware Dotnetnuke30/9/202217/6/2026
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
ModificadaMedia (5.4)0.67%—Dnnsoftware Dotnetnuke20/7/202217/6/2026
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
ModificadaAlta (7.5)1.1%—Dnnsoftware Dotnetnuke2/6/202217/6/2026
The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common…
ModificadaMedia (4.3)0.69%—Dnnsoftware Dotnetnuke6/4/202017/6/2026
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file…
ModificadaMedia (6.5)1.9%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
ModificadaAlta (8.8)2.4%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
ModificadaMedia (5.4)0.88%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
ModificadaMedia (6.1)6.2%—Dnnsoftware Dotnetnuke26/9/201917/6/2026
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.…
ModificadaAlta (7.5)54%—Dnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
AnalizadaAlta (7.5)74%⚠ Explotación activaDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
ModificadaAlta (7.5)47%—Dnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
AnalizadaAlta (7.5)76%⚠ Explotación activaDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
ModificadaMedia (6.1)1.1%—Dnnsoftware Dotnetnuke21/3/201917/6/2026
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
ModificadaAlta (7.5)13%—Dnnsoftware Dotnetnuke3/7/201817/6/2026
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
AnalizadaAlta (8.8)95%⚠ Explotación activaDnnsoftware Dotnetnuke20/7/201717/6/2026
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
ModificadaCrítica (9.8)75%—Dnnsoftware Dotnetnuke6/2/201717/6/2026
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
ModificadaMedia (5.4)0.66%—Dnnsoftware Dotnetnuke31/8/201617/6/2026
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.