Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 1.0% | — | Talentsys Consulting Inka.netAI | 23/9/2025 | 25/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection. This issue affects Inka.Net: before 6.7.1. | |
| Aplazada | Alta (8.8) | 0.77% | — | Microsoft Asp.netAIMicrosoft Diasymreader.dllAI | 8/9/2025 | 17/6/2026 | A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that… | |
| Aplazada | Alta (8.1) | 0.60% | — | Microsoft Asp.netAI | 8/9/2025 | 17/6/2026 | A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution. | |
| Analizada | Media (6.9) | 0.52% | — | Sun.net Ehrd Ctms | 1/9/2025 | 17/6/2026 | The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 17/6/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 30/9/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Media (5.1) | 0.26% | — | Sun.net Ehrd Ctms | 1/9/2025 | 30/9/2026 | The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Modificada | Crítica (9.3) | 0.48% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Crítica (10) | 0.54% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path. | |
| Modificada | Media (6.9) | 0.69% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution. | |
| Modificada | Crítica (9.3) | 0.50% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks. | |
| Modificada | Crítica (9.3) | 0.47% | — | Sun.net Ehrd Ctms | 30/8/2025 | 17/6/2026 | A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication. | |
| Aplazada | Alta (7) | 0.65% | — | Microsoft Asp.net CoreAI | 8/7/2025 | 17/6/2026 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry. | |
| Analizada | Crítica (9.8) | 0.82% | — | Mescius Activereports.net | 7/7/2025 | 17/6/2026 | Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but… | |
| Analizada | Crítica (9.8) | 0.82% | — | Mescius Activereports.net | 7/7/2025 | 17/6/2026 | Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but attack… | |
| Aplazada | Media (5.3) | 0.28% | — | Zealousweb Accept Authorize.net Payments Using Contact Form 7AI | 27/6/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5. | |
| Aplazada | Alta (8.1) | 0.72% | — | Serpednet Serped.netAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net serped-net allows PHP Local File Inclusion.This issue affects SERPed.net: from n/a through <= 4.6. | |
| Analizada | Media (4.9) | 0.23% | — | Couchbase .net SDK | 18/6/2025 | 17/6/2026 | The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell | 13/6/2025 | 17/6/2026 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Coinpayments.net Payment Gateway FOR WoocommerceAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woocommerce allows Object Injection.This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through <= 1.0.17. | |
| Analizada | Alta (8.4) | 0.17% | — | Blizzard Battle.net | 21/5/2025 | 17/6/2026 | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory. | |
| Aplazada | Alta (8.5) | 0.46% | — | Bunny.net BunnycdnAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue affects bunny.net: from n/a through <= 2.3.0. | |
| Analizada | Alta (7.5) | 24% | — | Progress Telerik UI FOR Asp.net Ajax | 14/5/2025 | 17/6/2026 | In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. | |
| Analizada | Alta (8) | 1.2% | — | Microsoft Build ToolsMicrosoft Visual Studio 2022Microsoft .net | 13/5/2025 | 17/6/2026 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.8% | — | Microsoft Msagsfeedback.azurewebsites.net | 8/5/2025 | 17/6/2026 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. |