Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.43% | — | Sun.net Ehrd Ctms | 2/5/2025 | 17/6/2026 | The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents. | |
| Aplazada | Media (6.1) | 0.24% | — | Mettler Toledo Freeweight.net WEB Reports ViewerAI | 22/4/2025 | 17/6/2026 | A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter. | |
| Aplazada | Alta (7.1) | 0.31% | — | Serpednet Serped.netAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net serped-net allows Reflected XSS.This issue affects SERPed.net: from n/a through <= 4.6. | |
| Aplazada | Media (4.7) | 0.10% | — | Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI | 9/4/2025 | 17/6/2026 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.… | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 8/4/2025 | 17/6/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Crítica (9.3) | 0.56% | — | Centralsquare Etrakit.net | 20/3/2025 | 17/6/2026 | A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no… | |
| Analizada | Alta (7) | 1.0% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 11/3/2025 | 17/6/2026 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.3) | 0.18% | — | Blizzard Battle.netAI | 1/3/2025 | 17/6/2026 | A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is… | |
| Analizada | Media (5.3) | 0.58% | — | Opcfoundation UA .net Standard Stack | 10/2/2025 | 17/6/2026 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints. | |
| Analizada | Alta (8.6) | 0.60% | — | Opcfoundation UA .net Standard Stack | 10/2/2025 | 17/6/2026 | Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled. | |
| Aplazada | Alta (8.5) | 0.46% | — | Serpednet Serped.netAI | 24/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serpednet SERPed.net serped-net allows SQL Injection.This issue affects SERPed.net: from n/a through <= 4.4. | |
| Aplazada | Alta (7.1) | 0.18% | — | Progpars.net Mybb Last TopicsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in progpars.net mybb Last Topics mybb-last-topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through <= 1.0. | |
| Aplazada | Alta (7.1) | 0.17% | — | Eyga.net Http TO Https Link ChangerAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4. | |
| Modificada | Alta (8.8) | 2.3% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft .net Framework | 14/1/2025 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 1.2% | — | Microsoft Visual Studio 2022Microsoft .net | 14/1/2025 | 17/6/2026 | .NET Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 1.8% | — | Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/1/2025 | 17/6/2026 | .NET Remote Code Execution Vulnerability | |
| Aplazada | Crítica (9.1) | 0.63% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714. | |
| Aplazada | Alta (7.5) | 0.52% | — | Syncfusion Essential Studio FOR Asp.net MVCAI | 15/12/2024 | 17/6/2026 | File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734. | |
| Aplazada | Media (5.1) | 0.14% | — | Devolutions Xts.netAI | 27/11/2024 | 17/6/2026 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks | |
| Analizada | Alta (7.5) | 2.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 12/11/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 3.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 12/11/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (8.1) | 1.2% | — | Apache Lucene.net | 31/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can… | |
| Analizada | Crítica (9.8) | 0.55% | — | Sun.net Ehrd Ctms | 28/10/2024 | 17/6/2026 | The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents. | |
| Analizada | Alta (7.5) | 0.40% | — | Sun.net Ehrd Ctms | 28/10/2024 | 17/6/2026 | The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user. |