Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.57% | — | Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.3) | 0.57% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 12/5/2026 | 15/7/2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (4.3) | 0.64% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 12/5/2026 | 18/6/2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited control over the destination of the… | |
| Aplazada | Alta (7.3) | 0.35% | — | Yetanotherforum Yaf.netAI | 12/5/2026 | 17/6/2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This… | |
| Aplazada | Alta (8.1) | 0.38% | — | Yetanotherforum.netAI | 12/5/2026 | 17/6/2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header into a JObject, serializes it with JsonConvert, and stores the result in the EventLog.Description column whenever an event… | |
| Aplazada | Alta (8.8) | 0.64% | — | Yetanotherforum Yaf.netAI | 12/5/2026 | 17/6/2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. The most impactful abuse is /Admin/RunSql, whose OnPostRunQuery binds Editor from the POST body and passes it straight to… | |
| Analizada | Alta (8.6) | 0.83% | — | Sun.net Ehrd CpasSun.net Ehrd Ctms | 2/5/2026 | 17/6/2026 | CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Alta (8.7) | 0.55% | — | Sun.net Ehrd Ctms | 2/5/2026 | 17/6/2026 | CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Crítica (9.8) | 0.73% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion. | |
| Modificada | Crítica (9.1) | 0.82% | — | Microsoft Asp.net Core | 21/4/2026 | 15/7/2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.3) | 0.65% | — | Digiwin Easyflow .net | 20/4/2026 | 17/6/2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Crítica (9.3) | 0.65% | — | Digiwin Easyflow .net | 20/4/2026 | 17/6/2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Pendiente de análisis | Crítica (9.1) | 0.81% | 💥 PoC | Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI | 16/4/2026 | 17/6/2026 | Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft .netMicrosoft .net Framework | 14/4/2026 | 25/7/2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.66% | — | Microsoft .net Framework | 14/4/2026 | 25/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/4/2026 | 15/7/2026 | Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 2.1% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/4/2026 | 15/7/2026 | Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Alta (7.5) | 2.3% | — | Microsoft .netMicrosoft Powershell | 14/4/2026 | 15/7/2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 1.3% | — | Microsoft .net Framework | 14/4/2026 | 15/7/2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Pendiente de análisis | Alta (8.8) | 0.27% | — | Asp.net Jvideo KITAI | 26/3/2026 | 17/6/2026 | ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information… | |
| Aplazada | Media (6.9) | 0.13% | — | Asprunner.netAI | 22/3/2026 | 17/6/2026 | ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash. | |
| Modificada | Alta (7.5) | 4.2% | — | Microsoft .net | 19/3/2026 | 17/6/2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing. | |
| Aplazada | Crítica (9.3) | 0.73% | — | Zkteco Zktime.netAI | 16/3/2026 | 17/6/2026 | ZKTeco ZKTime.Net 3.0.1.6 contains an insecure file permissions vulnerability that allows unprivileged users to escalate privileges by modifying executable files. Attackers can exploit world-writable permissions on the ZKTimeNet3.0 directory and its contents to replace executable files with malicious binaries for… | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft .net | 10/3/2026 | 17/6/2026 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. |