Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.27% | — | Microsoft DotnetAI | 8/9/2026 | 8/9/2026 | Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the… | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Media (6.5) | 0.65% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Analizada | Alta (7.5) | 0.77% | — | Apache Qpid Proton-dotnet | 5/8/2026 | 7/8/2026 | A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | |
| Aplazada | Crítica (9.2) | 0.66% | — | Spacelabs Healthcare SentinelAIMicrosoft IISAIMicrosoft DotnetAI | 2/6/2026 | 22/7/2026 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI… | |
| Analizada | Alta (8) | 0.36% | — | Dnnsoftware Dotnetnuke | 17/4/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are… | |
| Analizada | Media (6.9) | 0.29% | — | Dnnsoftware Dotnetnuke | 17/4/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. | |
| Analizada | Media (4.3) | 0.30% | — | Dnnsoftware Dotnetnuke | 17/4/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. | |
| Analizada | Media (5.1) | 0.31% | — | Dnnsoftware Dotnetnuke | 3/2/2026 | 17/6/2026 | DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF… | |
| Analizada | Media (5.4) | 0.22% | — | Dnnsoftware Dotnetnuke | 28/1/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0 contain a fix for the issue. | |
| Analizada | Media (5.4) | 0.28% | — | Dnnsoftware Dotnetnuke | 28/1/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name could include scripts that will run during some module operations in the Persona Bar. Versions 9.13.10 and 10.2.0… | |
| Analizada | Media (5.4) | 0.26% | — | Dnnsoftware Dotnetnuke | 28/1/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Versions 9.13.10 and… | |
| Analizada | Media (5.4) | 0.21% | — | Dnnsoftware Dotnetnuke | 28/1/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, a module could install with richtext in its description field which could contain scripts that will run for user in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a… | |
| Analizada | Media (4.8) | 0.19% | — | Dnnsoftware Dotnetnuke | 28/1/2026 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could inject scripts in module headers/footers that would run for other users. Versions 9.13.10 and 10.2.0 contain a fix for… | |
| Modificada | Media (6.1) | 0.21% | — | Dotnetfoundation Piranha CMS | 22/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field. | |
| Modificada | Media (6.1) | 0.21% | — | Dotnetfoundation Piranha CMS | 22/12/2025 | 5/7/2026 | A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field. | |
| Analizada | Crítica (9.8) | 47% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a… | |
| Analizada | Media (5.4) | 0.19% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix for CVE-2025-48378. This vulnerability is… | |
| Analizada | Media (4.3) | 0.23% | — | Dnnsoftware Dotnetnuke | 28/10/2025 | 17/6/2026 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the out-of-box experience for HTML editing allows unauthenticated users to upload files. This opens a potential vector to other security issues and is not needed on most implementations. This… | |
| Analizada | Media (6.1) | 0.29% | — | Dotnetfoundation Piranha CMS | 23/10/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. | |
| Aplazada | Alta (8.7) | 0.43% | — | Amazon ION DotnetAI | 9/10/2025 | 17/6/2026 | An infinite loop issue in Amazon.IonDotnet library versions <v1.3.2 may allow a threat actor to cause a denial of service through a specially crafted text input. To mitigate this issue, users should upgrade to version v1.3.2. As of August 20, 2025, this library has been deprecated and will not receive further updates. | |
| Analizada | Media (6.8) | 0.32% | — | Dotnetfoundation Piranha CMS | 26/9/2025 | 17/6/2026 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser. |