Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.21% | — | Arevico WP Simple RedirectAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arevico WP Simple Redirect wp-simple-redirect allows Reflected XSS.This issue affects WP Simple Redirect: from n/a through <= 1.1. | |
| Aplazada | Alta (7.6) | 0.32% | — | E-plugins Institutions DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3..4. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Alta (7.6) | 0.37% | — | E-plugins Lawyer DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Lawyer Directory lawyer-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Directory: from n/a through <= 1.3.3. | |
| Aplazada | Alta (8.8) | 0.47% | — | E-plugins Lawyer DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Lawyer Directory lawyer-directory allows Privilege Escalation.This issue affects Lawyer Directory: from n/a through <= 1.3.3. | |
| Analizada | Media (6.9) | 0.14% | — | Milner Imagedirector Capture | 20/1/2026 | 17/6/2026 | Use of Default Credentials, Hard-coded Credentials vulnerability in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows decryption of document archive files using credentials decrypted with hard-coded application encryption key. This issue affects ImageDirector Capture: from 7.0.9.0 before… | |
| Analizada | Alta (7.2) | 0.08% | — | Milner Imagedirector Capture | 20/1/2026 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm (DES) vulnerability in the Password class in C2SConnections.dll in Milner ImageDirector Capture on Windows allows Encryption Brute Forcing to obtain database credentials.This issue affects ImageDirector Capture: from 7.0.9.0 before 7.6.3.25808. | |
| Analizada | Alta (8.5) | 0.18% | — | Milner Imagedirector Capture | 20/1/2026 | 17/6/2026 | Insufficiently Protected Credentials, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Connection Settings dialog in Milner ImageDirector Capture on Windows allows Adversary in the Middle (AiTM) by modifying the 'Server' field to redirect client authentication.This issue affects… | |
| Analizada | Alta (8.5) | 0.19% | — | Milner Imagedirector Capture | 20/1/2026 | 17/6/2026 | Insufficiently Protected Credentials vulnerability in the Credential Field of Milner ImageDirector Capture allows retrieval of credential material and enables database access.This issue affects ImageDirector Capture: from 7.0.9 through 7.6.3.25808. | |
| Analizada | Alta (8.5) | 0.07% | — | Milner Imagedirector Capture | 20/1/2026 | 17/6/2026 | The use of a hard-coded encryption key in calls to the Password function in C2SGlobalSettings.dll in Milner ImageDirector Capture on Windows allows a local attacker to decrypt database credentials by reading the cryptographic key from the executable. This issue affects ImageDirector Capture: from 7.0.9 before… | |
| Aplazada | Alta (8.4) | 0.11% | — | IBM Sterling Connect Direct FOR UnixAI | 20/1/2026 | 17/6/2026 | IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to… | |
| Analizada | Media (5.5) | 0.38% | — | Phpgurukul Directory Management System | 19/1/2026 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Directory Management System 1.0. Impacted is an unknown function of the file /index.php of the component Search. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and… | |
| Aplazada | Media (4.4) | 0.27% | — | WMF Mobile RedirectorAI | 14/1/2026 | 17/6/2026 | The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to… | |
| Aplazada | Alta (7.2) | 0.37% | — | Name DirectoryAI | 14/1/2026 | 17/6/2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.8) | 0.54% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism | |
| Analizada | Alta (8.2) | 0.30% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file | |
| Analizada | Crítica (9.9) | 0.34% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges | |
| Analizada | Media (6.1) | 0.23% | — | Monospace Directus | 8/1/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.14.0, an open redirect vulnerability exists in the Directus SAML authentication callback endpoint. During SAML authentication, the `RelayState` parameter is intended to preserve the user's original destination.… | |
| Aplazada | Alta (7.1) | 0.22% | — | Cmsjunkie Wp-businessdirectoryAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Reflected XSS.This issue affects WP-BusinessDirectory: from n/a through <= 4.0.1. | |
| Aplazada | Media (6.5) | 0.29% | — | Page Expire Popup RedirectionAI | 6/1/2026 | 17/6/2026 | The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' shortcode attribute in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes… | |
| Aplazada | Media (4.3) | 0.30% | — | Digages Direct Payments WPAI | 31/12/2025 | 28/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Digages Direct Payments WP direct-payments-wp allows Retrieve Embedded Sensitive Data.This issue affects Direct Payments WP: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.3) | 0.26% | — | Digages Direct-payments-wpAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in Digages Direct Payments WP direct-payments-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Direct Payments WP: from n/a through <= 1.3.2. | |
| Aplazada | Media (5.3) | 0.25% | — | Reuters DirectAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Reuters News Agency Reuters Direct reuters-direct allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reuters Direct: from n/a through <= 3.0.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Solwininfotech Trash Duplicate AND 301 RedirectAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in solwininfotech Trash Duplicate and 301 Redirect trash-duplicate-and-301-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trash Duplicate and 301 Redirect: from n/a through <= 1.9.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Salephpscripts WEB Directory FreeAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows DOM-Based XSS.This issue affects Web Directory Free: from n/a through <= 1.7.12. |