Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)0.57%—Microsoft .net FrameworkMicrosoft .net12/5/202615/7/2026
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
ModificadaAlta (7.3)0.57%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net12/5/202615/7/2026
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
AnalizadaMedia (4.3)0.64%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net12/5/202618/6/2026
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the…
AplazadaAlta (7.3)0.35%—Yetanotherforum Yaf.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This…
AplazadaAlta (8.1)0.38%—Yetanotherforum.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a JObject, serializes it with JsonConvert, and stores the result in the EventLog.Description column whenever an event…
AplazadaAlta (8.8)0.64%—Yetanotherforum Yaf.netAI12/5/202617/6/2026
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor from the POST body and passes it straight to…
AnalizadaAlta (8.6)0.83%—Sun.net Ehrd CpasSun.net Ehrd Ctms2/5/202617/6/2026
CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.55%—Sun.net Ehrd Ctms2/5/202617/6/2026
CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaCrítica (9.8)0.73%—Progress Telerik UI FOR Asp.net Ajax22/4/202617/6/2026
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
AnalizadaAlta (7.5)0.49%—Progress Telerik UI FOR Asp.net Ajax22/4/202617/6/2026
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
ModificadaCrítica (9.1)0.82%—Microsoft Asp.net Core21/4/202615/7/2026
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.3)0.65%—Digiwin Easyflow .net20/4/202617/6/2026
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AnalizadaCrítica (9.3)0.65%—Digiwin Easyflow .net20/4/202617/6/2026
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Pendiente de análisisCrítica (9.1)0.81%💥 PoCMicrosoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI16/4/202617/6/2026
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
ModificadaAlta (7.5)2.4%—Microsoft .netMicrosoft .net Framework14/4/202625/7/2026
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.9)0.66%—Microsoft .net Framework14/4/202625/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)2.4%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/4/202615/7/2026
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)2.1%—Microsoft .netMicrosoft Visual Studio 202214/4/202615/7/2026
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
ModificadaAlta (7.5)2.3%—Microsoft .netMicrosoft Powershell14/4/202615/7/2026
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)1.3%—Microsoft .net Framework14/4/202615/7/2026
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
Pendiente de análisisAlta (8.8)0.27%—Asp.net Jvideo KITAI26/3/202617/6/2026
ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information…
AplazadaMedia (6.9)0.13%—Asprunner.netAI22/3/202617/6/2026
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.
ModificadaAlta (7.5)4.2%—Microsoft .net19/3/202617/6/2026
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
AplazadaCrítica (9.3)0.73%—Zkteco Zktime.netAI16/3/202617/6/2026
ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for…
AnalizadaAlta (7.8)0.31%—Microsoft .net10/3/202617/6/2026
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.