Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 26% | — | Blogengine.net | 26/6/2023 | 17/6/2026 | An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code. | |
| Modificada | Media (6.1) | 31% | — | Blogengine.net | 21/6/2023 | 17/6/2026 | Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect. | |
| Modificada | Media (5.3) | 0.43% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs. | |
| Modificada | Media (5.4) | 0.36% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post. | |
| Modificada | Media (5.4) | 0.38% | — | Blogengine.net | 6/3/2023 | 17/6/2026 | A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file. | |
| Modificada | Crítica (9.8) | 0.76% | — | Blogengine.net | 18/1/2023 | 17/6/2026 | BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/. | |
| Modificada | Alta (7.2) | 1.2% | — | Blogengine.net | 19/12/2022 | 17/6/2026 | An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | |
| Modificada | Media (4.8) | 0.55% | — | Blogengine.net | 2/9/2022 | 17/6/2026 | BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | |
| Modificada | Media (6.5) | 0.73% | — | Blogengine.net | 18/5/2022 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server. | |
| Modificada | Crítica (9.1) | 2.7% | — | Blogengine.net | 13/5/2022 | 17/6/2026 | BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. | |
| Modificada | Media (6.1) | 0.97% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx. | |
| Modificada | Alta (7.1) | 5.4% | — | Dotnetblogengine Blogengine.net | 3/7/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | |
| Modificada | Alta (8.8) | 7.1% | — | Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. | |
| Modificada | Alta (8.8) | 7.6% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. | |
| Modificada | Alta (7.5) | 2.7% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | |
| Modificada | Crítica (9.8) | 16% | — | Blogengine.net | 7/5/2019 | 17/6/2026 | BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | |
| Modificada | Crítica (9.8) | 32% | — | Blogengine.net | 21/3/2019 | 17/6/2026 | An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user… | |
| Modificada | Alta (7.5) | 2.3% | — | Blogengine E2 | 24/7/2014 | 17/6/2026 | SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process. | |
| Modificada | Media (5) | 1.3% | — | Dotnetblogengine Blogengine.net | 3/1/2014 | 17/6/2026 | BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. | |
| Modificada | Media (4.3) | 1.5% | — | Dotnetblogengine Blogengine.net | 16/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter. |