Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.46% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload. | |
| Analizada | Media (4.7) | 0.51% | — | Dotnetfoundation Piranha CMS | 20/12/2024 | 17/6/2026 | A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /manager/media. This PDF can contain malicious JavaScript code, which is executed when a victim user opens or interacts with the PDF in their web browser, leading to a XSS vulnerability. | |
| Analizada | Crítica (9.8) | 2.0% | — | Mihula ProdotnetzipDotnetzip.semverd Project Dotnetzip.semverd | 13/11/2024 | 17/6/2026 | Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code via the src/Zip.Shared/ZipEntry.Extract.cs component NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Alta (7.5) | 0.89% | — | Dotnetfoundation C# Language Server Protocol | 17/7/2023 | 17/6/2026 | A vulnerability has been found in OmniSharp csharp-language-server-protocol up to 0.19.6 and classified as problematic. This vulnerability affects the function CreateSerializerSettings of the file src/JsonRpc/Serialization/SerializerBase.cs of the component JSON Serializer. The manipulation leads to resource… | |
| Modificada | Media (5.4) | 0.43% | — | Dnnsoftware Dotnetnuke | 12/4/2023 | 17/6/2026 | An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file. | |
| Modificada | Media (4.9) | 1.3% | — | Dnnsoftware Dotnetnuke | 30/9/2022 | 17/6/2026 | Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. | |
| Modificada | Crítica (9.8) | 1.4% | — | Dotnetcore Agileconfig | 18/8/2022 | 17/6/2026 | Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access. | |
| Modificada | Media (5.4) | 0.67% | — | Dnnsoftware Dotnetnuke | 20/7/2022 | 17/6/2026 | DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. | |
| Modificada | Alta (7.5) | 1.1% | — | Dnnsoftware Dotnetnuke | 2/6/2022 | 17/6/2026 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common… | |
| Modificada | Alta (7.5) | 0.53% | — | Transloadit Tusdotnet | 22/11/2021 | 17/6/2026 | The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content. | |
| Modificada | Alta (8.1) | 0.46% | — | Dotnetfoundation Piranha CMS | 16/11/2021 | 17/6/2026 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known. | |
| Modificada | Crítica (9.8) | 1.1% | — | Starkbank Ecdsa-dotnet | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Media (5.4) | 0.65% | — | Dotnetfoundation Piranha CMS | 25/10/2021 | 17/6/2026 | In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution. | |
| Modificada | Alta (8.8) | 73% | — | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or… | |
| Modificada | Alta (8.1) | 1.8% | — | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>… | |
| Modificada | Media (4.3) | 0.69% | — | Dnnsoftware Dotnetnuke | 6/4/2020 | 17/6/2026 | There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file… | |
| Modificada | Media (6.5) | 1.9% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. | |
| Modificada | Alta (8.8) | 2.4% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). | |
| Modificada | Media (5.4) | 0.88% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). | |
| Modificada | Media (6.1) | 6.2% | — | Dnnsoftware Dotnetnuke | 26/9/2019 | 17/6/2026 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.5) | 54% | — | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812. | |
| Analizada | Alta (7.5) | 74% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | |
| Modificada | Alta (7.5) | 47% | — | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | |
| Analizada | Alta (7.5) | 76% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. |