Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.43%—Sun.net Ehrd Ctms2/5/202517/6/2026
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents.
AplazadaMedia (6.1)0.24%—Mettler Toledo Freeweight.net WEB Reports ViewerAI22/4/202517/6/2026
A cross-site scripting (reflected XSS) vulnerability was found in Mettler Toledo FreeWeight.Net Web Reports Viewer 8.4.0 (440). It allows an attacker to inject malicious scripts via the IW_SessionID_ parameter.
AplazadaAlta (7.1)0.31%—Serpednet Serped.netAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in serpednet SERPed.net serped-net allows Reflected XSS.This issue affects SERPed.net: from n/a through <= 4.6.
AplazadaMedia (4.7)0.10%—Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI9/4/202517/6/2026
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.…
AnalizadaAlta (7.5)1.7%—Microsoft Asp.net CoreMicrosoft Visual Studio 20228/4/202517/6/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaCrítica (9.3)0.56%—Centralsquare Etrakit.net20/3/202517/6/2026
A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote unauthenticated attacker can run arbitrary commands as the current MS SQL server account. It is recommended that the CRM feature is turned off while on eTRAKiT.net release 3.2.1.77. eTRAKiT.Net is no…
AnalizadaAlta (7)1.0%—Microsoft Asp.net CoreMicrosoft Visual Studio 202211/3/202517/6/2026
Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (7.3)0.18%—Blizzard Battle.netAI1/3/202517/6/2026
A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is…
AnalizadaMedia (5.3)0.58%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when using HTTPS endpoints.
AnalizadaAlta (8.6)0.60%—Opcfoundation UA .net Standard Stack10/2/202517/6/2026
Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application authentication when the deprecated Basic128Rsa15 security policy is enabled.
AplazadaAlta (8.5)0.46%—Serpednet Serped.netAI24/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in serpednet SERPed.net serped-net allows SQL Injection.This issue affects SERPed.net: from n/a through <= 4.4.
AplazadaAlta (7.1)0.18%—Progpars.net Mybb Last TopicsAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in progpars.net mybb Last Topics mybb-last-topics allows Stored XSS.This issue affects mybb Last Topics: from n/a through <= 1.0.
AplazadaAlta (7.1)0.17%—Eyga.net Http TO Https Link ChangerAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DSmidge HTTP to HTTPS link changer by Eyga.net https-links-in-content allows Stored XSS.This issue affects HTTP to HTTPS link changer by Eyga.net: from n/a through <= 0.2.4.
ModificadaAlta (8.8)2.3%—Microsoft .netMicrosoft Visual Studio 2017Microsoft .net Framework14/1/202517/6/2026
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
ModificadaAlta (7.3)1.2%—Microsoft Visual Studio 2022Microsoft .net14/1/202517/6/2026
.NET Elevation of Privilege Vulnerability
ModificadaAlta (7.5)1.8%—Microsoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019Microsoft Visual Studio 202214/1/202517/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
AnalizadaAlta (7.5)1.7%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202214/1/202517/6/2026
.NET Remote Code Execution Vulnerability
AplazadaCrítica (9.1)0.63%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.
AplazadaAlta (7.5)0.52%—Syncfusion Essential Studio FOR Asp.net MVCAI15/12/202417/6/2026
File Manager in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 has a traversal issue that is related to the request parameter, aka I644734.
AplazadaMedia (5.1)0.14%—Devolutions Xts.netAI27/11/202417/6/2026
Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks
AnalizadaAlta (7.5)2.6%—Microsoft .netMicrosoft Visual Studio 202212/11/202417/6/2026
.NET and Visual Studio Denial of Service Vulnerability
AnalizadaCrítica (9.8)3.6%—Microsoft .netMicrosoft Visual Studio 202212/11/202417/6/2026
.NET and Visual Studio Remote Code Execution Vulnerability
AnalizadaAlta (8.1)1.2%—Apache Lucene.net31/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic between a replication client and server, or control the target replication node URL, can…
AnalizadaCrítica (9.8)0.55%—Sun.net Ehrd Ctms28/10/202417/6/2026
The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents.
AnalizadaAlta (7.5)0.40%—Sun.net Ehrd Ctms28/10/202417/6/2026
The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user.