Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Dot-notes Project Dot-notes1/9/202017/6/2026
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.
ModificadaMedia (4.3)0.69%—Dnnsoftware Dotnetnuke6/4/202017/6/2026
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file…
ModificadaMedia (5.3)1.1%—DOT Project DOT6/4/202017/6/2026
eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.
ModificadaAlta (8.8)2.1%—DOT Project DOT15/3/202017/6/2026
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
ModificadaMedia (6.5)1.9%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
ModificadaAlta (8.8)2.4%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
ModificadaMedia (5.4)0.88%—Dnnsoftware Dotnetnuke24/2/202017/6/2026
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
ModificadaMedia (6.3)1.1%—Dot-object Project Dot-object18/2/202017/6/2026
dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
ModificadaAlta (7.8)2.2%—Valvesoftware Dota 217/2/202017/6/2026
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.
ModificadaCrítica (9.8)95%—Dotcms5/2/202017/6/2026
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into…
ModificadaAlta (7.3)3.1%—Dot-prop Project Dot-prop4/2/202017/6/2026
Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.
ModificadaAlta (7.8)1.9%—Valvesoftware Dota 227/1/202017/6/2026
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
ModificadaAlta (7.8)1.9%—Valvesoftware Dota 227/1/202017/6/2026
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
ModificadaAlta (7.8)1.9%—Valvesoftware Dota 227/1/202017/6/2026
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call.
ModificadaAlta (7.8)4.2%💥 ExploitValvesoftware Dota 227/1/202017/6/2026
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.
ModificadaMedia (6.1)6.2%💥 ExploitDnnsoftware Dotnetnuke26/9/201917/6/2026
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.…
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.5)54%💥 ExploitDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
AnalizadaAlta (7.5)74%⚠ Explotación activa💥 ExploitDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
ModificadaAlta (7.5)47%💥 ExploitDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
AnalizadaAlta (7.5)76%⚠ Explotación activa💥 ExploitDnnsoftware Dotnetnuke3/7/201917/6/2026
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
ModificadaMedia (6.1)0.97%—Dotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
ModificadaAlta (7.1)5.4%💥 ExploitDotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
ModificadaAlta (7.5)1.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
ModificadaAlta (8.8)7.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.