Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)1.2%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.29%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+214/7/202624/7/2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.8)0.84%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)0.78%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net14/7/202622/7/2026
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+414/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+414/7/202624/7/2026
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net14/7/202622/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.7%—Microsoft .net FrameworkMicrosoft Azure Active Directory14/7/202624/7/2026
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202624/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202616/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.9)0.81%—Apache Lucene.net3/7/20268/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the…
AnalizadaMedia (4)0.47%—Apache Lucene.net3/7/20268/7/2026
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
AnalizadaAlta (8.9)0.72%—Apache Lucene.net3/7/20268/7/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the…
Pendiente de análisisAlta (7.5)1.2%—Microsoft Openapi.netAI30/6/20262/7/2026
The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through…
AplazadaAlta (7.7)0.45%—Digiwin Easyflow .netAI22/6/202622/6/2026
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in.
AplazadaMedia (5.1)0.28%—Digiwin Easyflow .netAI22/6/202622/6/2026
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
ModificadaAlta (7.5)2.4%—Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net9/6/202623/7/2026
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.5)0.37%—Microsoft .net9/6/202623/7/2026
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
ModificadaAlta (7.8)0.42%—Microsoft .net9/6/202623/7/2026
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
ModificadaAlta (7.5)2.4%—Microsoft .net12/5/202615/7/2026
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.