Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 30% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2019+1 | 25/2/2021 | 17/6/2026 | .NET Core Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 3.3% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017+1 | 25/2/2021 | 17/6/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (6.7) | 0.82% | — | Microsoft Powershellget | 16/10/2020 | 17/6/2026 | <p>A security feature bypass vulnerability exists in the PowerShellGet V2 module. An attacker who successfully exploited this vulnerability could bypass WDAC (Windows Defender Application Control) policy and execute arbitrary code on a policy locked-down machine.</p> <p>An attacker must have administrator privileges… | |
| Modificada | Media (6.5) | 3.2% | — | Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+6 | 15/9/2020 | 17/6/2026 | A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or… | |
| Modificada | Media (6.7) | 6.6% | — | Microsoft PowershellMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 11/9/2020 | 17/6/2026 | <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC.</p> <p>To exploit the vulnerability, an… | |
| Modificada | Alta (7.5) | 6.4% | — | Microsoft .netMicrosoft .net CoreMicrosoft .net FrameworkMicrosoft Visual Studio 2017+3 | 21/5/2020 | 19/8/2026 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without… | |
| Modificada | Alta (7.5) | 5.3% | — | Microsoft .net CoreMicrosoft Powershell Core | 11/9/2019 | 17/6/2026 | A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'. | |
| Modificada | Media (4.1) | 1.1% | — | Microsoft Powershell Core | 19/7/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | |
| Modificada | Media (5.9) | 4.5% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft Visual Studio 2017Microsoft .net Framework | 5/3/2019 | 17/6/2026 | A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0631. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0627, CVE-2019-0632. | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows Server 2016Microsoft Windows Server 2019 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard, aka 'Windows Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0631, CVE-2019-0632. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+5 | 14/11/2018 | 17/6/2026 | A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server 2019, Windows Server 2012, Windows 8.1,… | |
| Modificada | Alta (8.8) | 23% | — | Microsoft.powershell.archiveMicrosoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7+6 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008… | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Asp.net CoreMicrosoft Powershell Core | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0. | |
| Modificada | Media (5.5) | 0.75% | — | Microsoft .net FrameworkMicrosoft Powershell CoreMicrosoft .net CoreMicrosoft .net Framework Developer Pack+1 | 11/7/2018 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1,… | |
| Modificada | Crítica (9.8) | 22% | — | Microsoft PowershellMicrosoft Powershell Editor Services | 11/7/2018 | 17/6/2026 | A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension. | |
| Modificada | Alta (7.5) | 9.1% | — | Microsoft Asp.net CoreMicrosoft Powershell Core | 14/3/2018 | 17/6/2026 | .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability". | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability." | |
| Modificada | Alta (7.5) | 8.9% | — | Microsoft .net CoreMicrosoft Powershell CoreMicrosoft .net Framework | 10/1/2018 | 17/6/2026 | Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765. |