Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.97% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx. | |
| Modificada | Alta (7.1) | 5.4% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | |
| Modificada | Alta (8.8) | 7.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. | |
| Modificada | Alta (7.5) | 2.7% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | |
| Modificada | Media (6.1) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/3/2019 | 17/6/2026 | DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. | |
| Modificada | Media (5.5) | 10% | — | Dotnetzip.semverd Project Dotnetzip.semverd | 25/7/2018 | 17/6/2026 | DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (7.8) | 1.5% | — | Yamldotnet Project Yamldotnet | 13/7/2018 | 17/6/2026 | YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can… | |
| Modificada | Alta (7.5) | 13% | — | Dnnsoftware Dotnetnuke | 3/7/2018 | 17/6/2026 | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources. | |
| Analizada | Alta (8.8) | 95% | ⚠ Explotación activa | Dnnsoftware Dotnetnuke | 20/7/2017 | 17/6/2026 | DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | |
| Modificada | Crítica (9.8) | 75% | — | Dnnsoftware Dotnetnuke | 6/2/2017 | 17/6/2026 | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx. | |
| Modificada | Media (5.4) | 0.66% | — | Dnnsoftware Dotnetnuke | 31/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. | |
| Modificada | Media (4.3) | 1.8% | — | Dnnsoftware Dotnetnuke | 9/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 17/6/2026 | Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 2.5% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI. | |
| Modificada | Baja (3.5) | 0.94% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile. | |
| Modificada | Media (5) | 1.3% | — | Dotnetblogengine Blogengine.net | 3/1/2014 | 17/6/2026 | BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. | |
| Modificada | Media (4.3) | 0.92% | — | Dnnsoftware DotnetnukeDotnetnuke | 11/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message. | |
| Modificada | Media (4.3) | 0.92% | — | Dnnsoftware Dotnetnuke | 11/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup. | |
| Modificada | Media (4.3) | 1.5% | — | Dnnsoftware Dotnetnuke | 9/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | — | Dnnsoftware Dotnetnuke | 29/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page. | |
| Modificada | Media (5) | 1.2% | — | Dnnsoftware Dotnetnuke | 29/11/2009 | 16/6/2026 | The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation. | |
| Modificada | Media (5) | 1.3% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors. | |
| Modificada | Media (6.5) | 1.2% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity." |