Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 1.1% | — | Dotclear | 19/12/2025 | 17/6/2026 | Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the uploaded file is accessed, enabling arbitrary… | |
| Analizada | Alta (8.7) | 0.94% | — | Dotclear | 10/12/2025 | 26/9/2026 | Dotclear 2.29 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the media upload functionality. Attackers can exploit the file upload process by crafting a PHP shell with a command execution form to gain system access through the uploaded file. | |
| Analizada | Alta (7) | 0.09% | — | Jetbrains DottraceJetbrains ResharperJetbrains Rider | 10/11/2025 | 25/9/2026 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition | |
| Analizada | Crítica (9.8) | 47% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a… | |
| Analizada | Media (5.4) | 0.19% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is… | |
| Analizada | Media (4.3) | 0.23% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations. This… | |
| Analizada | Media (6.1) | 0.29% | — | Dotnetfoundation Piranha CMS | 23/10/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. | |
| Aplazada | Media (6.5) | 0.22% | — | Dotcamp Ultimate BlocksAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows Stored XSS.This issue affects Ultimate Blocks: from n/a through <= 3.3.6. | |
| Aplazada | Alta (8.7) | 0.43% | — | Amazon ION DotnetAI | 9/10/2025 | 17/6/2026 | An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates. | |
| Analizada | Media (6.8) | 0.32% | — | Dotnetfoundation Piranha CMS | 26/9/2025 | 17/6/2026 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser. | |
| Analizada | Media (6.1) | 0.21% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, DNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that is returned to the browser. In these cases, the application… | |
| Analizada | Media (5.9) | 0.19% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection, affecting any unsuspecting user clicking such link. This issue has been patched in version 10.1.0. | |
| Analizada | Media (5.3) | 0.26% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request can be made to upload a file with Unicode… | |
| Analizada | Media (4.8) | 0.18% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, administrators and content editors can set html in module titles that could include javascript which could be used for XSS based attacks. This issue has been patched in version 10.1.0. | |
| Analizada | Crítica (9) | 0.49% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain… | |
| Analizada | Media (5.4) | 0.18% | — | Dnnsoftware Dotnetnuke | 23/9/2025 | 30/9/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the context of the website and to any other… | |
| Analizada | Media (6.5) | 0.43% | — | Dnnsoftware Dotnetnuke | 22/9/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients… | |
| Aplazada | Crítica (9.4) | 1.7% | — | DotcmsAI | 4/9/2025 | 17/6/2026 | dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpoint. This endpoint uses the sites query parameter, which accepts a comma-separated list of site identifiers or keys. The vulnerability was triggered via the sites parameter, which was directly… | |
| Aplazada | Media (5.3) | 1.3% | — | Aiondadotcom Mcp-sshAI | 29/8/2025 | 17/6/2026 | A security flaw has been discovered in AiondaDotCom mcp-ssh up to 1.0.3. Affected by this issue is some unknown functionality of the file server-simple.mjs. Performing manipulation results in command injection. The attack can be initiated remotely. Upgrading to version 1.0.4 and 1.1.0 can resolve this issue. The patch… | |
| Aplazada | Baja (1.9) | 0.13% | — | Boquan DotwalletAI | 4/8/2025 | 17/6/2026 | A vulnerability was found in Boquan DotWallet App 2.15.2 on Android and classified as problematic. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.boquanhash.dotwallet. The manipulation leads to improper export of android application components. The attack… | |
| Aplazada | Alta (7.1) | 0.21% | — | Karimmughal DOT Html PHP XML ETC PagesAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in karimmughal Dot html,php,xml etc pages dot-htmlphpxml-etc-pages allows Reflected XSS.This issue affects Dot html,php,xml etc pages: from n/a through <= 1.0. | |
| Analizada | Alta (8.6) | 36% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted series of malicious interaction to potentially expose NTLM hashes to a third party SMB server. This issue has been patched in version… | |
| Analizada | Alta (8.8) | 0.35% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 7.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request or proxy to be created that could bypass the design of DNN Login IP Filters allowing login attempts from IP Addresses not in… | |
| Analizada | Media (6.1) | 0.23% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects. This issue has been patched in version… | |
| Analizada | Media (5.1) | 0.21% | — | Dnnsoftware Dotnetnuke | 21/6/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in the feed. This issue has been patched… |