Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.26% | — | Ayecode Geodirectory | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.80. | |
| Aplazada | Alta (7.1) | 0.32% | — | Salephpscripts WEB Directory FreeAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.3. | |
| Aplazada | Media (6.5) | 0.26% | — | Jeroen Peters Name DirectoryAI | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.29.0. | |
| Analizada | Media (6.5) | 0.35% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | |
| Analizada | Crítica (9.8) | 0.40% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | |
| Analizada | Media (6.1) | 0.24% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. | |
| Analizada | Crítica (9.1) | 0.44% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000. | |
| Analizada | Alta (7.5) | 0.37% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000. | |
| Analizada | Media (6.1) | 0.24% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000. | |
| Analizada | Crítica (9.1) | 5.6% | 💥 Exploit | Salephpscripts WEB Directory Free | 30/8/2024 | 17/6/2026 | The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues. | |
| Analizada | Alta (8.8) | 0.44% | — | Ayecode Geodirectory | 18/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61. | |
| Modificada | Crítica (9.8) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 16/8/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user. IBM X-Force ID: 228570. | |
| Analizada | Media (6.3) | 0.58% | — | Opentext Directory Services | 12/8/2024 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | |
| Modificada | Alta (7.5) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 30/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID:… | |
| Analizada | Media (6.8) | 0.50% | — | Salephpscripts WEB Directory Free | 30/7/2024 | 17/6/2026 | The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (8.3) | 0.57% | — | Opentext Directory ServicesAI | 26/7/2024 | 17/6/2026 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2. | |
| Modificada | Media (5.4) | 0.28% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Alta (7.5) | 0.38% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | |
| Modificada | Alta (8.8) | 0.66% | — | Designinvento Directorypress | 22/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10. | |
| Modificada | Media (6.1) | 0.33% | — | Wpdirectorykit WP Directory KIT | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpdirectorykit.Com WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.3.5. | |
| Aplazada | Media (6.3) | 0.28% | — | Opentext Netiq Directory AND Resource AdministratorAI | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10. | |
| Modificada | Media (5.4) | 0.34% | — | Quantumcloud Simple Video Directory | 12/7/2024 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.92% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/7/2024 | 17/6/2026 | A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Analizada | Baja (2.7) | 0.32% | — | Wpdirectorykit WP Directory KIT | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP Directory Kit: from n/a through 1.3.6. |