Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Dnnsoftware Dotnetnuke | 22/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality." | |
| Modificada | Media (4.3) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths." | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dnnsoftware Dotnetnuke | 7/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (4.6) | 1.6% | — | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files. | |
| Modificada | Media (6.8) | 1.00% | — | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors. | |
| Modificada | Media (5.1) | 2.5% | 💥 Exploit | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dotnetblogengine Blogengine.net | 16/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (6.4) | 1.9% | — | Dnnsoftware Dotnetnuke | 5/3/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Dotnetindex Ikon Admanager | 16/12/2008 | 16/6/2026 | Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.2% | — | Dotnetnuke Iframe | 1/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values." | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Dotnetindex Active News Manager | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Dotnetindex Active News Manager | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Dotnetindex Active News Manager | 24/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Dnnsoftware Dotnetnuke | 25/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter. | |
| Modificada | Alta (10) | 2.5% | — | Dnnsoftware Dotnetnuke | 18/7/2006 | 16/6/2026 | ** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected,… | |
| Modificada | Media (4.3) | 1.3% | — | Dotnetbb Forums | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Dotnetindex Active News Manager | 31/5/2005 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Media (4.3) | 1.3% | — | Dnnsoftware Dotnetnuke | 19/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log. | |
| Modificada | Media (5) | 1.4% | — | Dnnsoftware Dotnetnuke | 31/12/2004 | 16/6/2026 | DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Dnnsoftware Dotnetnuke | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx. |