Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
755 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.20% | — | Digiwin Easyflow .netAI | 30/9/2026 | 30/9/2026 | EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Pendiente de análisis | Media (6.5) | 0.29% | — | Io.netty Netty-codec-memcacheAI | 18/9/2026 | 25/9/2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server can exploit this type mismatch by sending a specially crafted response. This can… | |
| Aplazada | Media (6.1) | 0.27% | — | Cutesoft Components Cute Editor FOR Asp.netAI | 17/9/2026 | 22/9/2026 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component,… | |
| Pendiente de análisis | Alta (7.5) | 0.62% | — | Ssh.netAI | 16/9/2026 | 30/9/2026 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot safely quote every remote command interpreter. When an application passes an… | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7.5) | 1.2% | — | Microsoft Asp.net CoreAI | 8/9/2026 | 8/9/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7) | 0.76% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.84% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.9) | 0.88% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 30/9/2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Pendiente de análisis | Alta (7.1) | 0.42% | — | Ssh.netAI | 18/8/2026 | 18/9/2026 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without containment validation, allowing a malicious,… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 11/8/2026 | 17/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 8/9/2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft .net Framework | 11/8/2026 | 14/8/2026 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 11/8/2026 | 13/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft .net | 11/8/2026 | 3/9/2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.35% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory. | |
| Analizada | Media (5.3) | 0.43% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion. |