Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.36%—Accredible Credential.netAI16/4/202417/6/2026
The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue."
AplazadaMedia (5.9)0.32%—Bunny.netAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.Net allows Stored XSS.This issue affects bunny.Net: from n/a through 2.0.1.
AnalizadaMedia (6.2)0.89%—Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+39/4/202417/6/2026
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
ModificadaAlta (7.3)2.5%💥 PoCMicrosoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 20229/4/202417/6/2026
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
AnalizadaAlta (7.5)99%⚠ Explotación activa💥 ExploitMicrosoft .net Framework23/3/202417/6/2026
.NET Framework Information Disclosure Vulnerability
ModificadaMedia (6.5)0.49%—Honeywell Masmobile Asp.net ServicesHoneywell Masmobile Classic16/3/202417/6/2026
Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history.
AnalizadaAlta (7.5)3.0%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+412/3/202417/6/2026
Microsoft QUIC Denial of Service Vulnerability
AnalizadaAlta (7.5)3.1%—Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 202212/3/202417/6/2026
.NET and Visual Studio Denial of Service Vulnerability
AnalizadaAlta (8.1)1.0%—Fullstackhero .net 9 Starter KIT29/2/202417/6/2026
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.
ModificadaAlta (7.5)2.7%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.5)2.4%—Microsoft Asp.net CoreMicrosoft Visual Studio 202213/2/202410/8/2026
.NET Denial of Service Vulnerability
ModificadaAlta (7.5)0.53%—Truelayer.net30/1/202417/6/2026
TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could…
ModificadaMedia (6.8)2.9%—Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 20229/1/202417/6/2026
Microsoft Identity Denial of service vulnerability
ModificadaAlta (7.5)3.6%—Microsoft .net Framework9/1/202417/6/2026
.NET Framework Denial of Service Vulnerability
ModificadaAlta (7.5)2.9%—Microsoft .net9/1/202417/6/2026
.NET Denial of Service Vulnerability
ModificadaCrítica (9.8)2.8%—Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net9/1/202417/6/2026
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
ModificadaAlta (8.7)1.2%—Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+29/1/202417/6/2026
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
ModificadaAlta (7.5)33%💥 PoCNewtonsoft Json.net3/1/202414/7/2026
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote…
ModificadaMedia (6.1)0.45%—Spassarop Owasp Antisamy .net2/1/202417/6/2026
OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0, there is a potential for a mutation cross-site scripting (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the…
ModificadaMedia (6.1)0.46%—Aspnetzero Asp.net Zero26/12/202317/6/2026
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
ModificadaMedia (5.3)0.79%—Opcfoundation Ua-.netstandard12/12/202317/6/2026
The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.
ModificadaMedia (5.4)0.63%—Michaelschwarz Ajax.net Professional5/12/202317/6/2026
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users…
ModificadaMedia (4.3)0.66%—Elastic APM .net Agent22/11/202317/6/2026
The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized…
ModificadaMedia (5.5)1.1%—Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 202214/11/202317/6/2026
ASP.NET Core Security Feature Bypass Vulnerability
ModificadaAlta (7.5)2.8%—Microsoft Visual Studio 2022Microsoft Asp.net Core14/11/202317/6/2026
ASP.NET Core Denial of Service Vulnerability