Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)26%—Blogengine.net26/6/202317/6/2026
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
ModificadaMedia (6.1)31%—Blogengine.net21/6/202317/6/2026
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
ModificadaMedia (5.3)0.43%—Blogengine.net6/3/202317/6/2026
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
ModificadaMedia (5.4)0.36%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post.
ModificadaMedia (5.4)0.38%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
ModificadaCrítica (9.8)0.76%—Blogengine.net18/1/202317/6/2026
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~/App_Data/.
ModificadaAlta (7.2)1.2%—Blogengine.net19/12/202217/6/2026
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
ModificadaMedia (4.8)0.55%—Blogengine.net2/9/202217/6/2026
BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/api/posts. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
ModificadaMedia (6.5)0.73%—Blogengine.net18/5/202217/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability discovered in BlogEngine.Net v3.3.8.0 allows unauthenticated attackers to read arbitrary files on the hosting web server.
ModificadaCrítica (9.1)2.7%—Blogengine.net13/5/202217/6/2026
BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request.
ModificadaMedia (6.1)0.97%—Dotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
ModificadaAlta (7.1)5.4%—Dotnetblogengine Blogengine.net3/7/201917/6/2026
BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter.
ModificadaAlta (7.5)1.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
ModificadaAlta (8.8)7.1%—Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.
ModificadaAlta (8.8)7.6%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714.
ModificadaAlta (7.5)2.7%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
ModificadaCrítica (9.8)16%—Blogengine.net7/5/201917/6/2026
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
ModificadaCrítica (9.8)32%—Blogengine.net21/3/201917/6/2026
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in PostList.ascx.cs can cause unauthenticated users to load a PostView.ascx component from a potentially untrusted location on the local filesystem. This is especially dangerous if an authenticated user…
ModificadaAlta (7.5)2.3%—Blogengine E224/7/201417/6/2026
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.
ModificadaMedia (5)1.3%—Dotnetblogengine Blogengine.net3/1/201417/6/2026
BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.
ModificadaMedia (4.3)1.5%—Dotnetblogengine Blogengine.net16/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.