Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.24%—CM Business DirectoryAI26/9/202517/6/2026
The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaAlta (7.1)0.13%—Wpdirectorykit Sweet Energy EfficiencyAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPDirectoryKit Sweet Energy Efficiency sweet-energy-efficiency allows Stored XSS.This issue affects Sweet Energy Efficiency: from n/a through <= 1.0.8.
AplazadaMedia (6.5)0.27%—E-plugins Directory PROAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5.
AnalizadaBaja (2.1)0.35%—Phpgurukul Directory Management System29/8/202517/6/2026
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly…
AplazadaAlta (8.1)0.33%—Emarketdesign Employee Directory Staff Listing Team DirectoryAI28/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5.
AplazadaCrítica (9.8)0.37%💥 PoCQuantumcloud Simple Business Directory PROAI20/8/202517/6/2026
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
AplazadaAlta (7.1)0.23%—Quantumcloud Simple Link DirectoryAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1.
AplazadaAlta (7.1)0.23%—Quantumcloud Simple Business Directory PROAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1.
AplazadaAlta (8.8)0.33%—Real Spaces Wordpress Properties Directory ThemeAI19/8/202517/6/2026
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.37%💥 PoCReal Spaces Wordpress Properties Directory ThemeAI19/8/202517/6/2026
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to…
AnalizadaMedia (4.3)0.26%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.
AnalizadaMedia (6.1)0.25%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
AnalizadaMedia (5.3)0.29%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.
AnalizadaMedia (6.1)0.34%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
AplazadaMedia (6.4)0.25%—Employee DirectoryAI5/8/202517/6/2026
The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (6.4)0.25%—Campus DirectoryAI5/8/202517/6/2026
The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
ModificadaAlta (8.1)0.63%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
ModificadaMedia (4.3)0.82%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
ModificadaAlta (8.8)2.1%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
ModificadaAlta (8.8)1.8%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
ModificadaAlta (7.5)0.34%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format.
ModificadaAlta (8.8)0.98%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers.
ModificadaAlta (8.8)0.48%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password.