Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.18% | — | Sarah Giles Dynamic User DirectoryAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Giles Dynamic User Directory dynamic-user-directory allows Stored XSS.This issue affects Dynamic User Directory: from n/a through <= 2.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Designinvento DirectorypressAI | 27/10/2025 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25. | |
| Aplazada | Alta (7.1) | 0.25% | — | E-plugins Directory PROAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows Reflected XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Aplazada | Crítica (9.8) | 0.73% | 💥 PoC | Quantumcloud Simple Link DirectoryAI | 22/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Alta (8.8) | 0.80% | — | System Security Services Daemon SssdAIMicrosoft Active DirectoryAIMIT KerberosAI | 9/10/2025 | 31/8/2026 | A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fallback to the an2ln plugin is possible. This fallback allows an attacker with… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Search AND GO - DirectoryAI | 9/10/2025 | 17/6/2026 | The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.29% | — | Wpdirectorykit WP Directory KITAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDirectoryKit WP Directory Kit wpdirectorykit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through <= 1.4.0. | |
| Aplazada | Media (6.4) | 0.24% | — | CM Business DirectoryAI | 26/9/2025 | 17/6/2026 | The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Alta (7.1) | 0.13% | — | Wpdirectorykit Sweet Energy EfficiencyAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows Stored XSS.This issue affects Sweet Energy Efficiency: from n/a through <= 1.0.8. | |
| Aplazada | Media (6.5) | 0.27% | — | E-plugins Directory PROAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Analizada | Baja (2.1) | 0.35% | — | Phpgurukul Directory Management System | 29/8/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (8.1) | 0.33% | — | Emarketdesign Employee Directory Staff Listing Team DirectoryAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5. | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Link DirectoryAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1. | |
| Aplazada | Alta (8.8) | 0.33% | — | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.3) | 0.26% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users. | |
| Analizada | Media (5.4) | 0.24% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this. | |
| Analizada | Media (6.1) | 0.25% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data. | |
| Analizada | Media (5.3) | 0.29% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources. | |
| Analizada | Media (5.4) | 0.24% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access. | |
| Analizada | Media (6.1) | 0.34% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189. | |
| Aplazada | Media (6.4) | 0.25% | — | Employee DirectoryAI | 5/8/2025 | 17/6/2026 | The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.25% | — | Campus DirectoryAI | 5/8/2025 | 17/6/2026 | The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… |