Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.1%—Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell13/6/202517/6/2026
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.23%—Devolutions Remote Desktop ManagerDevolutions Remote Desktop Manager Powershell10/2/202517/6/2026
Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and…
AnalizadaAlta (7.5)1.7%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/1/202517/6/2026
.NET Remote Code Execution Vulnerability
AplazadaAlta (8.8)0.44%—Ironman Powershell UniversalAI27/10/202417/6/2026
Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.
AnalizadaMedia (6.3)1.2%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/5/202417/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
ModificadaAlta (7.3)2.5%—Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 20229/4/202417/6/2026
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
AnalizadaAlta (7.5)3.0%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+412/3/202417/6/2026
Microsoft QUIC Denial of Service Vulnerability
AnalizadaAlta (7.5)3.1%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202212/3/202417/6/2026
.NET and Visual Studio Denial of Service Vulnerability
ModificadaCrítica (9.8)2.8%—Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net9/1/202417/6/2026
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
ModificadaAlta (8.8)2.1%—Ironmansoftware Powershell Universal23/11/202317/6/2026
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
ModificadaMedia (6.5)1.4%—Microsoft Powershell20/11/202317/6/2026
PowerShell Information Disclosure Vulnerability
ModificadaAlta (7.8)0.26%—Psappdeploytoolkit Powershell APP Deployment Toolkit1/8/202317/6/2026
In PowerShell App Deployment Toolkit (aka PSAppDeployToolkit) through 3.8.0, an incorrect access control vulnerability in the default configuration may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.8%—Microsoft .netMicrosoft PowershellFedoraproject Fedora10/1/202317/6/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.8)1.1%—Microsoft PowershellMicrosoft Remote Desktop ClientMicrosoft Windows 10Microsoft Windows 11+813/12/202217/6/2026
Windows Graphics Component Elevation of Privilege Vulnerability
ModificadaAlta (8.5)61%—Microsoft PowershellMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 7+713/12/202217/6/2026
PowerShell Remote Code Execution Vulnerability
ModificadaAlta (7.2)2.0%—Ironmansoftware Powershell Universal14/11/202217/6/2026
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which allows a remote attacker with administrator privilege to create, delete, update, and display files outside of the configuration directory via a crafted HTTP request to…
ModificadaAlta (8.8)0.82%—Ironmansoftware Powershell Universal14/11/202217/6/2026
Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve other app tokens by ID via an HTTP web request. Patched Versions are 3.5.3, 3.4.7, and 2.12.6.
ModificadaMedia (5.9)2.4%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell9/8/202217/6/2026
.NET Spoofing Vulnerability
ModificadaAlta (7.5)5.7%—Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+210/5/202217/6/2026
.NET and Visual Studio Denial of Service Vulnerability
ModificadaAlta (7.8)0.65%—Microsoft PowershellMicrosoft Windows 10Microsoft Windows 11Microsoft Windows 8.1+615/4/202217/6/2026
PowerShell Elevation of Privilege Vulnerability
ModificadaMedia (6.3)1.6%—Microsoft .netMicrosoft .net CoreMicrosoft PowershellMicrosoft Visual Studio 2019+29/3/202217/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)2.3%—Microsoft Powershell15/12/202117/6/2026
Microsoft PowerShell Spoofing Vulnerability
ModificadaMedia (5.7)20%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 201913/10/202117/6/2026
.NET Core and Visual Studio Information Disclosure Vulnerability
ModificadaMedia (5.5)1.5%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+112/8/202110/8/2026
.NET Core and Visual Studio Information Disclosure Vulnerability
ModificadaAlta (7.5)3.9%—Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+112/8/202110/8/2026
.NET Core and Visual Studio Denial of Service Vulnerability