Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.36% | — | Accredible Credential.netAI | 16/4/2024 | 17/6/2026 | The API in Accredible Credential.net December 6th, 2023 allows an Insecure Direct Object Reference attack that discloses partial information about certificates and their respective holder. NOTE: the excellium-services.com web page about this issue mentions "Vendor says that it's not a security issue." | |
| Aplazada | Media (5.9) | 0.32% | — | Bunny.netAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bunny.Net allows Stored XSS.This issue affects bunny.Net: from n/a through 2.0.1. | |
| Analizada | Media (6.2) | 0.89% | — | Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+3 | 9/4/2024 | 17/6/2026 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.3) | 2.5% | 💥 PoC | Microsoft .net FrameworkMicrosoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 9/4/2024 | 17/6/2026 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft .net Framework | 23/3/2024 | 17/6/2026 | .NET Framework Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 0.49% | — | Honeywell Masmobile Asp.net ServicesHoneywell Masmobile Classic | 16/3/2024 | 17/6/2026 | Authorization bypass can be achieved by session ID prediction in MASmobile Classic Android version 1.16.18 and earlier and MASmobile Classic iOS version 1.7.24 and earlier which allows remote attackers to retrieve sensitive data including customer data, security system status, and event history. | |
| Analizada | Alta (7.5) | 3.0% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022Microsoft Windows 11 21h2+4 | 12/3/2024 | 17/6/2026 | Microsoft QUIC Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 3.1% | — | Microsoft .netMicrosoft PowershellMicrosoft Visual Studio 2022 | 12/3/2024 | 17/6/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Analizada | Alta (8.1) | 1.0% | — | Fullstackhero .net 9 Starter KIT | 29/2/2024 | 17/6/2026 | A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request. | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 0.53% | — | Truelayer.net | 30/1/2024 | 17/6/2026 | TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could… | |
| Modificada | Media (6.8) | 2.9% | — | Microsoft .netMicrosoft Identity ModelMicrosoft Visual Studio 2022 | 9/1/2024 | 17/6/2026 | Microsoft Identity Denial of service vulnerability | |
| Modificada | Alta (7.5) | 3.6% | — | Microsoft .net Framework | 9/1/2024 | 17/6/2026 | .NET Framework Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.9% | — | Microsoft .net | 9/1/2024 | 17/6/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Crítica (9.8) | 2.8% | — | Microsoft PowershellMicrosoft Visual Studio 2022Microsoft .net FrameworkMicrosoft .net | 9/1/2024 | 17/6/2026 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.7) | 1.2% | — | Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+2 | 9/1/2024 | 17/6/2026 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 33% | 💥 PoC | Newtonsoft Json.net | 3/1/2024 | 14/7/2026 | Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote… | |
| Modificada | Media (6.1) | 0.45% | — | Spassarop Owasp Antisamy .net | 2/1/2024 | 17/6/2026 | OWASP AntiSamy .NET is a library for performing cleansing of HTML coming from untrusted sources. Prior to version 1.2.0, there is a potential for a mutation cross-site scripting (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the… | |
| Modificada | Media (6.1) | 0.46% | — | Aspnetzero Asp.net Zero | 26/12/2023 | 17/6/2026 | An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages. | |
| Modificada | Media (5.3) | 0.79% | — | Opcfoundation Ua-.netstandard | 12/12/2023 | 17/6/2026 | The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely. | |
| Modificada | Media (5.4) | 0.63% | — | Michaelschwarz Ajax.net Professional | 5/12/2023 | 17/6/2026 | Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users… | |
| Modificada | Media (4.3) | 0.66% | — | Elastic APM .net Agent | 22/11/2023 | 17/6/2026 | The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is possible the headers will not be sanitized… | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | ASP.NET Core Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft Visual Studio 2022Microsoft Asp.net Core | 14/11/2023 | 17/6/2026 | ASP.NET Core Denial of Service Vulnerability |