Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.27%—Cutesoft Components Cute Editor FOR Asp.netAI17/9/202622/9/2026
Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a victim in a browser session authenticated to a site running the vulnerable component,…
Pendiente de análisisAlta (7.5)1.2%—Microsoft Asp.net CoreAI8/9/20268/9/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (5.9)0.88%—Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net8/9/202630/9/2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.35%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.
AnalizadaMedia (5.3)0.43%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
AnalizadaMedia (6.5)0.42%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication…
AnalizadaAlta (8.1)0.50%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
AnalizadaAlta (7.5)0.36%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
AnalizadaMedia (5.9)0.16%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
AnalizadaAlta (8.1)0.34%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
AnalizadaAlta (8.1)0.73%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
AnalizadaAlta (8.1)0.67%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.
AnalizadaAlta (7.5)0.27%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit…
AnalizadaAlta (7.5)0.45%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
AnalizadaAlta (7.5)0.45%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
AnalizadaAlta (8.1)0.68%—Progress Telerik UI FOR Asp.net Ajax22/7/20266/8/2026
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202624/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core OdataMicrosoft Odata WEB API14/7/202616/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
ModificadaAlta (7.5)2.4%—Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net9/6/202623/7/2026
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.73%—Progress Telerik UI FOR Asp.net Ajax22/4/202617/6/2026
In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible.
AnalizadaAlta (7.5)0.49%—Progress Telerik UI FOR Asp.net Ajax22/4/202617/6/2026
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
ModificadaCrítica (9.1)0.82%—Microsoft Asp.net Core21/4/202615/7/2026
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisCrítica (9.1)0.81%—Microsoft Asp.netAIMicrosoft IISAIDigital Knowledge KnowledgedeliverAI16/4/202617/6/2026
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
Pendiente de análisisAlta (8.8)0.27%—Asp.net Jvideo KITAI26/3/202617/6/2026
ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information…
ModificadaAlta (7.5)2.4%—Microsoft Asp.net Core10/3/202615/7/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.