Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.45%—GeodirectoryAI26/7/202517/6/2026
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaMedia (5.1)0.36%—RsdirectoryAIJoomlaAI18/7/202517/6/2026
A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
AplazadaMedia (6.1)0.28%—Netwrix Directory ManagerAI17/7/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392.
AplazadaCrítica (9.3)0.38%—Cmsjunkie Wp-businessdirectoryAI16/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Blind SQL Injection.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.4.
ModificadaMedia (5.9)0.23%—Ayecode Geodirectory11/7/202517/6/2026
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaMedia (6.3)0.29%—Opentext Directory ServicesAI10/7/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4.
AplazadaAlta (8.5)0.29%—Quantumcloud Simple Link DirectoryAI4/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1.
AplazadaMedia (5)0.16%—Oneidentity Onelogin Active Directory ConnectorAI2/7/202517/6/2026
In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
AnalizadaBaja (2.1)0.40%—Phpgurukul Directory Management System20/6/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (2.1)0.40%—Phpgurukul Directory Management System20/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit…
AnalizadaBaja (2.1)0.40%—Phpgurukul Directory Management System20/6/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaMedia (5.5)0.49%—Phpgurukul Directory Management System20/6/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaAlta (7.8)0.17%—IBM Security Verify Directory15/6/202517/6/2026
IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.
AplazadaMedia (6.4)0.22%—Campus DirectoryAI4/6/202517/6/2026
The Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes.…
AplazadaMedia (6.4)0.22%—Employee DirectoryAI4/6/202517/6/2026
The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes.…
AnalizadaCrítica (10)0.40%—Netwrix Directory Manager29/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
AnalizadaCrítica (9.1)0.43%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
AnalizadaMedia (5)0.25%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.
AnalizadaMedia (5.3)0.34%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
AnalizadaMedia (6.5)0.27%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.
AplazadaCrítica (9.8)0.49%—Quantumcloud Simple Business Directory PROAI23/5/202517/6/2026
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
AplazadaMedia (4.3)0.23%—Jeroen Peters Name DirectoryAI19/5/202517/6/2026
Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0.
AnalizadaMedia (5.3)0.48%—Phpgurukul Directory Management System18/5/202517/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The…
AplazadaMedia (5.3)0.31%—Quantumcloud Simple Link DirectoryAI16/5/202517/6/2026
Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1.
AnalizadaCrítica (9.8)0.65%—Quantumcloud Simple Video Directory15/5/202517/6/2026
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Orbitaley — Vulnerabilidades