Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.7)0.46%—Dotnetfoundation Piranha CMS20/12/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload.
AnalizadaMedia (4.7)0.51%—Dotnetfoundation Piranha CMS20/12/202417/6/2026
A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability.
AnalizadaCrítica (9.8)2.0%—Mihula ProdotnetzipDotnetzip.semverd Project Dotnetzip.semverd13/11/202417/6/2026
Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
ModificadaAlta (7.5)0.89%—Dotnetfoundation C# Language Server Protocol17/7/202317/6/2026
A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource…
ModificadaMedia (5.4)0.43%—Dnnsoftware Dotnetnuke12/4/202317/6/2026
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
ModificadaMedia (4.9)1.3%—Dnnsoftware Dotnetnuke30/9/202217/6/2026
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
ModificadaCrítica (9.8)1.4%—Dotnetcore Agileconfig18/8/202217/6/2026
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
ModificadaMedia (5.4)0.67%—Dnnsoftware Dotnetnuke20/7/202217/6/2026
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
ModificadaAlta (7.5)1.1%—Dnnsoftware Dotnetnuke2/6/202217/6/2026
The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common…
ModificadaAlta (7.5)0.53%—Transloadit Tusdotnet22/11/202117/6/2026
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
ModificadaAlta (8.1)0.46%—Dotnetfoundation Piranha CMS16/11/202117/6/2026
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
ModificadaCrítica (9.8)1.1%—Starkbank Ecdsa-dotnet9/11/202117/6/2026
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
ModificadaMedia (5.4)0.65%—Dotnetfoundation Piranha CMS25/10/202117/6/2026
In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.
ModificadaAlta (8.8)73%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or…
ModificadaAlta (8.1)1.8%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>…
ModificadaMedia (4.3)0.69%—Dnnsoftware Dotnetnuke6/4/202017/6/2026
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file…
ModificadaMedia (6.5)1.9%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
ModificadaAlta (8.8)2.4%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
ModificadaMedia (5.4)0.88%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
ModificadaMedia (6.1)6.2%—Dnnsoftware Dotnetnuke26/9/201917/6/2026
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.…
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.5)54%—Dnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
AnalizadaAlta (7.5)74%⚠ Explotación activaDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
ModificadaAlta (7.5)47%—Dnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
AnalizadaAlta (7.5)76%⚠ Explotación activaDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.