Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%—Microsoft Asp.net Core10/3/202615/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .netMicrosoft Bcl.memory10/3/202617/6/2026
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.3)0.53%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is…
AnalizadaBaja (2.1)0.71%—Go2ismail Asp.net-core-inventory-order-management-system26/2/202617/6/2026
A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public…
AnalizadaMedia (4.4)0.18%—ImagemagickDlemstra Magick.net26/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel…
AnalizadaAlta (7.1)0.20%—ImagemagickDlemstra Magick.net26/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability occurs when processing an image with small dimension using the `-wavelet-denoise` operator. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
AnalizadaMedia (5.9)0.30%—Progress Telerik UI FOR Asp.net Ajax25/2/202617/6/2026
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
AnalizadaMedia (5.3)0.53%—ImagemagickDlemstra Magick.net24/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allocated but never freed. Version 7.1.2-15…
AnalizadaMedia (5.5)0.19%—ImagemagickDlemstra Magick.net24/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size…
AnalizadaAlta (7.5)0.46%—ImagemagickDlemstra Magick.net24/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to…
AnalizadaMedia (5.3)0.42%—ImagemagickDlemstra Magick.net24/2/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
AnalizadaAlta (7.5)1.1%—Microsoft .net10/2/202617/6/2026
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.48%—ImagemagickDlemstra Magick.net22/1/202617/6/2026
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion…
AplazadaBaja (3.7)0.24%—Amazon AWS SDK FOR .netAIAmazon S3AIAmazon DynamodbAIAmazon GlacierAI10/1/202617/6/2026
AWS SDK for .NET works with Amazon Web Services to help build scalable solutions with Amazon S3, Amazon DynamoDB, Amazon Glacier, and more. From versions 4.0.0 to before 4.0.3.3, Customer applications could be configured to improperly route AWS API calls to non-existent or non-AWS hosts. This notification is related…
AnalizadaCrítica (9.3)0.59%—Sun.net Wmpro29/12/20257/10/2026
WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaAlta (8.7)0.54%—Sun.net Wmpro29/12/20257/10/2026
WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.
AplazadaMedia (6)0.11%—Amazon S3 Encryption Client FOR .netAI17/12/202517/6/2026
Missing cryptographic key commitment in the Amazon S3 Encryption Client for .NET may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record. To mitigate this issue,…
AplazadaMedia (4.3)0.24%—Gravitec.net WEB Push NotificationsAI9/12/202517/6/2026
Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17.
AnalizadaAlta (7.2)0.67%—Cslanet Csla .net9/12/202530/9/2026
CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and is vulnerable to remote code execution during deserialization. This vulnerability…
AplazadaAlta (7.1)0.35%—Digiwin Easyflow .netAIDigiwin Easyflow AinetAI3/11/202517/6/2026
EasyFlow .NET and EasyFlow AiNet developed by Digiwin has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.
AplazadaAlta (8.7)0.45%—Digiwin Easyflow .netAIDigiwin Easyflow AinetAI21/10/202517/6/2026
EasyFlow .NET and EasyFlow AiNet, developed by Digiwin, has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to obtain database administrator credentials via a specific functionality.
ModificadaCrítica (9.9)66%💥 ExploitMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/10/202517/6/2026
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
AnalizadaMedia (5.7)0.72%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202214/10/202517/6/2026
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.3)0.61%—Microsoft .net14/10/202517/6/2026
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
AplazadaCrítica (9.3)0.31%—Akka.netAI6/10/202517/6/2026
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of inbound connections. Akka.Remote, however,…