Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.53% | — | Sun.net Ehrd Ctms | 28/10/2024 | 17/6/2026 | The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities. | |
| Aplazada | Media (5.3) | 0.50% | — | Opcfoundation UA .net StandardAI | 22/10/2024 | 17/6/2026 | An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to degrade gradually. | |
| Modificada | Alta (8.8) | 0.44% | — | Naudinvladimir Ferma.ru.net | 20/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mrcheck116 FERMA.ru.net ferma-ru-net-checkout allows Blind SQL Injection.This issue affects FERMA.ru.net: from n/a through <= 1.3.3. | |
| Modificada | Media (6.1) | 0.17% | — | Avchat.net Avchat Video Chat | 20/10/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stefan Nour AVChat Video Chat avchat-3 allows Stored XSS.This issue affects AVChat Video Chat: from n/a through <= 2.2. | |
| Analizada | Alta (7.5) | 3.1% | — | Microsoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 3.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 2.9% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 8/10/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (8.1) | 2.1% | — | Microsoft Visual Studio 2022Microsoft .net | 8/10/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 2.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 13/8/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft .netMicrosoft Visual Studio 2022 | 13/8/2024 | 17/6/2026 | .NET and Visual Studio Information Disclosure Vulnerability | |
| Analizada | Media (6.5) | 0.60% | — | Digiwin Easyflow .net | 2/8/2024 | 17/6/2026 | Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files from the remote server . | |
| Aplazada | Media (4.7) | 0.53% | — | Duende IdentityserverAIMicrosoft Asp.net CoreAI | 31/7/2024 | 17/6/2026 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party,… | |
| Aplazada | Crítica (9.8) | 1.5% | — | Cslanet Csla .netAI | 22/7/2024 | 17/6/2026 | Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter component. | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.3) | 1.3% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 2.6% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 2.9% | — | Microsoft .netMicrosoft Visual Studio 2022 | 9/7/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Aplazada | Alta (7.5) | 0.56% | — | Opcfoundation.netstandard.opc.ua.coreAI | 5/7/2024 | 17/6/2026 | A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an excessive number of messages from a remote source. This could potentially lead to a denial of service (DoS)… | |
| Aplazada | Crítica (9.8) | 0.63% | — | Digiwin Easyflow .netAI | 3/6/2024 | 17/6/2026 | DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records. | |
| Aplazada | Crítica (9.8) | 0.79% | — | Digiwin Easyflow .netAI | 15/5/2024 | 17/6/2026 | DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Analizada | Media (5.9) | 1.7% | — | Microsoft .netMicrosoft Visual Studio 2022 | 14/5/2024 | 17/6/2026 | Visual Studio Denial of Service Vulnerability | |
| Analizada | Media (6.3) | 1.2% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 14/5/2024 | 17/6/2026 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 1.0% | — | Opcfoundation Ua-.netstandard | 7/5/2024 | 17/6/2026 | OPC Foundation UA .NET Standard ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Baja (3.9) | 0.19% | — | Microsoft Msal.netAI | 16/4/2024 | 17/6/2026 | The MSAL library enabled acquisition of security tokens to call protected APIs. MSAL.NET applications targeting Xamarin Android and .NET Android (e.g., MAUI) using the library from versions 4.48.0 to 4.60.0 are impacted by a low severity vulnerability. A malicious application running on a customer Android device can… |