Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 1.2% | — | Microsoft Asp.net CoreAI | 8/9/2026 | 8/9/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.9) | 0.88% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 8/9/2026 | 30/9/2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core OdataMicrosoft Odata WEB API | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Asp.net Core OdataMicrosoft Odata WEB API | 14/7/2026 | 16/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net | 9/6/2026 | 23/7/2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Modificada | Crítica (9.1) | 0.82% | — | Microsoft Asp.net Core | 21/4/2026 | 15/7/2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net Core | 10/3/2026 | 15/7/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.3) | 0.53% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is… | |
| Analizada | Baja (2.1) | 0.71% | — | Go2ismail Asp.net-core-inventory-order-management-system | 26/2/2026 | 17/6/2026 | A vulnerability has been found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected is an unknown function of the component Administrative Interface. Such manipulation leads to execution after redirect. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.9) | 66% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/10/2025 | 17/6/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | |
| Aplazada | Alta (7) | 0.65% | — | Microsoft Asp.net CoreAI | 8/7/2025 | 17/6/2026 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry. | |
| Aplazada | Media (4.7) | 0.10% | — | Microsoft Identity WEBAIMicrosoft Identity AbstractionsAIMicrosoft Asp.net CoreAI | 9/4/2025 | 17/6/2026 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This vulnerability affects confidential client applications, including daemons, web apps, and web APIs.… | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 8/4/2025 | 17/6/2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7) | 0.98% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 11/3/2025 | 17/6/2026 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (4.7) | 0.53% | — | Duende IdentityserverAIMicrosoft Asp.net CoreAI | 31/7/2024 | 17/6/2026 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to a third-party,… | |
| Modificada | Alta (7.5) | 2.7% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2022 | 13/2/2024 | 10/8/2026 | .NET Denial of Service Vulnerability | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 14/11/2023 | 17/6/2026 | ASP.NET Core Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 2.8% | — | Microsoft Visual Studio 2022Microsoft Asp.net Core | 14/11/2023 | 17/6/2026 | ASP.NET Core Denial of Service Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Alta (7.5) | 14% | ⚠ Explotación activa | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022Fedoraproject Fedora | 8/8/2023 | 10/8/2026 | .NET and Visual Studio Denial of Service Vulnerability | |
| Modificada | Alta (7.5) | 1.9% | — | Microsoft .netMicrosoft Asp.net CoreMicrosoft Visual Studio 2022 | 8/8/2023 | 10/8/2026 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 11/10/2022 | 17/6/2026 | NuGet Client Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 4.0% | — | Microsoft .netMicrosoft .net CoreMicrosoft Visual Studio 2019Microsoft Visual Studio 2022+1 | 13/9/2022 | 17/6/2026 | .NET Core and Visual Studio Denial of Service Vulnerability | |
| Modificada | Media (5.9) | 2.4% | — | Microsoft .netMicrosoft .net CoreMicrosoft Powershell | 9/8/2022 | 17/6/2026 | .NET Spoofing Vulnerability |