Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | Dot-notes Project Dot-notes | 1/9/2020 | 17/6/2026 | All versions of package dot-notes are vulnerable to Prototype Pollution via the create function. | |
| Modificada | Media (4.3) | 0.69% | — | Dnnsoftware Dotnetnuke | 6/4/2020 | 17/6/2026 | There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file… | |
| Modificada | Media (5.3) | 1.1% | — | DOT Project DOT | 6/4/2020 | 17/6/2026 | eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload. | |
| Modificada | Alta (8.8) | 2.1% | — | DOT Project DOT | 15/3/2020 | 17/6/2026 | The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype. | |
| Modificada | Media (6.5) | 1.9% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions. | |
| Modificada | Alta (8.8) | 2.4% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). | |
| Modificada | Media (5.4) | 0.88% | — | Dnnsoftware Dotnetnuke | 24/2/2020 | 17/6/2026 | DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). | |
| Modificada | Media (6.3) | 1.1% | — | Dot-object Project Dot-object | 18/2/2020 | 17/6/2026 | dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Alta (7.8) | 2.2% | — | Valvesoftware Dota 2 | 17/2/2020 | 17/6/2026 | meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled. | |
| Modificada | Crítica (9.8) | 95% | — | Dotcms | 5/2/2020 | 17/6/2026 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into… | |
| Modificada | Alta (7.3) | 3.1% | — | Dot-prop Project Dot-prop | 4/2/2020 | 17/6/2026 | Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects. | |
| Modificada | Alta (7.8) | 1.9% | — | Valvesoftware Dota 2 | 27/1/2020 | 17/6/2026 | rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption. | |
| Modificada | Alta (7.8) | 1.9% | — | Valvesoftware Dota 2 | 27/1/2020 | 17/6/2026 | meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption. | |
| Modificada | Alta (7.8) | 1.9% | — | Valvesoftware Dota 2 | 27/1/2020 | 17/6/2026 | meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call. | |
| Modificada | Alta (7.8) | 4.2% | 💥 Exploit | Valvesoftware Dota 2 | 27/1/2020 | 17/6/2026 | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call. | |
| Modificada | Media (6.1) | 6.2% | 💥 Exploit | Dnnsoftware Dotnetnuke | 26/9/2019 | 17/6/2026 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc.… | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812. | |
| Analizada | Alta (7.5) | 74% | ⚠ Explotación activa💥 Exploit | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811. | |
| Modificada | Alta (7.5) | 47% | 💥 Exploit | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy. | |
| Analizada | Alta (7.5) | 76% | ⚠ Explotación activa💥 Exploit | Dnnsoftware Dotnetnuke | 3/7/2019 | 17/6/2026 | DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters. | |
| Modificada | Media (6.1) | 0.97% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx. | |
| Modificada | Alta (7.1) | 5.4% | 💥 Exploit | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | |
| Modificada | Alta (8.8) | 7.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. |