Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Dnnsoftware Dotnetnuke22/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."
ModificadaMedia (4.3)1.1%—Dnnsoftware Dotnetnuke21/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter.
ModificadaMedia (4.3)1.1%—Dnnsoftware Dotnetnuke21/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
ModificadaMedia (4.3)1.5%💥 ExploitDnnsoftware Dotnetnuke7/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (4.6)1.6%—Dnnsoftware Dotnetnuke30/3/200916/6/2026
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.
ModificadaMedia (6.8)1.00%—Dnnsoftware Dotnetnuke30/3/200916/6/2026
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
ModificadaMedia (5.1)2.5%💥 ExploitDnnsoftware Dotnetnuke30/3/200916/6/2026
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
ModificadaMedia (4.3)1.5%💥 ExploitDotnetblogengine Blogengine.net16/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (6.4)1.9%—Dnnsoftware Dotnetnuke5/3/200916/6/2026
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
ModificadaMedia (5)2.6%💥 ExploitDotnetindex Ikon Admanager16/12/200816/6/2026
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb.
ModificadaMedia (5)7.4%💥 ExploitDotnetindex Professional Download Assistant15/12/200816/6/2026
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.
ModificadaAlta (7.5)2.4%💥 ExploitDotnetindex Professional Download Assistant15/12/200816/6/2026
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.2%—Dotnetnuke Iframe1/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in the IFrame module before 03.02.01 for DotNetNuke (DNN) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "Pass through values."
ModificadaAlta (7.5)3.7%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.
ModificadaAlta (7.5)1.4%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by…
ModificadaMedia (4.3)1.9%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (4.3)1.9%💥 ExploitDnnsoftware Dotnetnuke25/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
ModificadaAlta (10)2.5%—Dnnsoftware Dotnetnuke18/7/200616/6/2026
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected,…
ModificadaMedia (4.3)1.3%—Dotnetbb Forums28/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.
ModificadaAlta (7.5)1.3%—Dotnetindex Active News Manager31/5/200516/6/2026
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaMedia (4.3)1.3%—Dnnsoftware Dotnetnuke19/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
ModificadaMedia (5)1.4%—Dnnsoftware Dotnetnuke31/12/200416/6/2026
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
ModificadaMedia (4.3)1.5%💥 ExploitAspdotnetstorefront31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
ModificadaMedia (4.3)2.2%💥 ExploitAspdotnetstorefront31/12/200416/6/2026
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
ModificadaAlta (7.5)1.2%—Dnnsoftware Dotnetnuke31/12/200416/6/2026
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
Orbitaley — Vulnerabilidades