Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)1.0%—Talentsys Consulting Inka.netAI23/9/202525/9/2026
Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection. This issue affects Inka.Net: before 6.7.1.
AplazadaAlta (8.8)0.77%—Microsoft Asp.netAIMicrosoft Diasymreader.dllAI8/9/202517/6/2026
A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read. Per CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that…
AplazadaAlta (8.1)0.60%—Microsoft Asp.netAI8/9/202517/6/2026
A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution.
AnalizadaMedia (6.9)0.52%—Sun.net Ehrd Ctms1/9/202517/6/2026
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202517/6/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202530/9/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaMedia (5.1)0.26%—Sun.net Ehrd Ctms1/9/202530/9/2026
The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
ModificadaCrítica (9.3)0.48%—Sun.net Ehrd Ctms30/8/202517/6/2026
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.
ModificadaCrítica (10)0.54%—Sun.net Ehrd Ctms30/8/202517/6/2026
An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via a malicious file by controlling the destination file path.
ModificadaMedia (6.9)0.69%—Sun.net Ehrd Ctms30/8/202517/6/2026
An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a specific file, which may lead to arbitrary code execution.
ModificadaCrítica (9.3)0.50%—Sun.net Ehrd Ctms30/8/202517/6/2026
A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the absence of proper access control checks.
ModificadaCrítica (9.3)0.47%—Sun.net Ehrd Ctms30/8/202517/6/2026
A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality without prior authentication.
AplazadaAlta (7)0.65%—Microsoft Asp.net CoreAI8/7/202517/6/2026
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
AnalizadaCrítica (9.8)0.82%—Mescius Activereports.net7/7/202517/6/2026
Mescius ActiveReports.NET TypeResolutionService Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but…
AnalizadaCrítica (9.8)0.82%—Mescius Activereports.net7/7/202517/6/2026
Mescius ActiveReports.NET ReadValue Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mescius ActiveReports.NET. Interaction with this library is required to exploit this vulnerability but attack…
AplazadaMedia (5.3)0.28%—Zealousweb Accept Authorize.net Payments Using Contact Form 7AI27/6/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in ZealousWeb Accept Authorize.NET Payments Using Contact Form 7 accept-authorize-net-payments-using-contact-form-7 allows Retrieve Embedded Sensitive Data.This issue affects Accept Authorize.NET Payments Using Contact Form 7: from n/a through <= 2.5.
AplazadaAlta (8.1)0.72%—Serpednet Serped.netAI27/6/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in serpednet SERPed.net serped-net allows PHP Local File Inclusion.This issue affects SERPed.net: from n/a through <= 4.6.
AnalizadaMedia (4.9)0.23%—Couchbase .net SDK18/6/202517/6/2026
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
AnalizadaAlta (7.5)1.1%—Microsoft Visual Studio 2022Microsoft .netMicrosoft Powershell13/6/202517/6/2026
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
AplazadaCrítica (9.8)0.46%—Coinpayments.net Payment Gateway FOR WoocommerceAI23/5/202517/6/2026
Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpayments-payment-gateway-for-woocommerce allows Object Injection.This issue affects CoinPayments.net Payment Gateway for WooCommerce: from n/a through <= 1.0.17.
AnalizadaAlta (8.4)0.17%—Blizzard Battle.net21/5/202517/6/2026
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.
AplazadaAlta (8.5)0.46%—Bunny.net BunnycdnAI19/5/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.net bunny.net bunnycdn allows Stored XSS.This issue affects bunny.net: from n/a through <= 2.3.0.
AnalizadaAlta (7.5)24%—Progress Telerik UI FOR Asp.net Ajax14/5/202517/6/2026
In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
AnalizadaAlta (8)1.2%—Microsoft Build ToolsMicrosoft Visual Studio 2022Microsoft .net13/5/202517/6/2026
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.8%—Microsoft Msagsfeedback.azurewebsites.net8/5/202517/6/2026
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.