Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.45% | — | GeodirectoryAI | 26/7/2025 | 17/6/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.1) | 0.36% | — | RsdirectoryAIJoomlaAI | 18/7/2025 | 17/6/2026 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component. | |
| Aplazada | Media (6.1) | 0.28% | — | Netwrix Directory ManagerAI | 17/7/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Cmsjunkie Wp-businessdirectoryAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Blind SQL Injection.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.4. | |
| Modificada | Media (5.9) | 0.23% | — | Ayecode Geodirectory | 11/7/2025 | 17/6/2026 | The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.3) | 0.29% | — | Opentext Directory ServicesAI | 10/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4. | |
| Aplazada | Alta (8.5) | 0.29% | — | Quantumcloud Simple Link DirectoryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.49% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.8) | 0.17% | — | IBM Security Verify Directory | 15/6/2025 | 17/6/2026 | IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges. | |
| Aplazada | Media (6.4) | 0.22% | — | Campus DirectoryAI | 4/6/2025 | 17/6/2026 | The Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (6.4) | 0.22% | — | Employee DirectoryAI | 4/6/2025 | 17/6/2026 | The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Analizada | Crítica (10) | 0.40% | — | Netwrix Directory Manager | 29/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. | |
| Analizada | Crítica (9.1) | 0.43% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data. | |
| Analizada | Media (5) | 0.25% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource. | |
| Analizada | Media (5.3) | 0.34% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password. | |
| Analizada | Media (6.5) | 0.27% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Media (4.3) | 0.23% | — | Jeroen Peters Name DirectoryAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0. | |
| Analizada | Media (5.3) | 0.48% | — | Phpgurukul Directory Management System | 18/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.31% | — | Quantumcloud Simple Link DirectoryAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Analizada | Crítica (9.8) | 0.65% | — | Quantumcloud Simple Video Directory | 15/5/2025 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. |