Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.6)0.82%—Nuget GalleryAI14/4/202624/7/2026
NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend job’s handling of .nuspec files within NuGet packages. An attacker can supply a crafted nuspec file with malicious metadata, leading to cross package metadata injection that may result in remote…
AplazadaMedia (6.5)0.28%—Gnuget MF Plus WpmlAI4/7/202517/6/2026
Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MF Plus WPML: from n/a through <= 1.1.
AnalizadaMedia (6.9)0.38%—Microsoft Nugetgallery6/12/202417/6/2026
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allows attackers to…
AnalizadaMedia (6.1)0.76%—Microsoft Nugetgallery1/10/202417/6/2026
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.
AnalizadaMedia (6.1)0.65%—Microsoft Nugetgallery12/6/202417/6/2026
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allows attackers to…
ModificadaAlta (7.1)1.1%—Microsoft Nuget14/6/202317/6/2026
NuGet Client Remote Code Execution Vulnerability
ModificadaMedia (5.8)0.79%—Microsoft .net FrameworkMicrosoft Nuget9/11/202210/8/2026
.NET Framework Information Disclosure Vulnerability
ModificadaMedia (5.5)5.6%—Microsoft Visual Studio 2022Microsoft .netMicrosoft .net CoreMicrosoft Nuget+215/6/202217/6/2026
.NET and Visual Studio Information Disclosure Vulnerability
ModificadaCrítica (9.1)1.5%—Jenkins Nuget25/5/202117/6/2026
Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaMedia (5.4)1.6%—Microsoft Nugetgallery9/6/202017/6/2026
A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery Spoofing Vulnerability'.
ModificadaAlta (8.8)3.8%—Microsoft Active Directory Authentication LibraryMicrosoft Nuget14/8/201917/6/2026
An elevation of privilege vulnerability exists in Azure Active Directory Authentication Library On-Behalf-Of flow, in the way the library caches tokens. This vulnerability allows an authenticated attacker to perform actions in context of another user. The authenticated attacker can exploit this vulneraiblity by…
ModificadaMedia (5.5)1.2%—Microsoft Nuget16/5/201917/6/2026
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'.
ModificadaMedia (6.5)2.7%—Microsoft Visual Studio 2017Microsoft NugetMono-project Mono FrameworkMicrosoft .net Core SDK+49/4/201917/6/2026
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.