Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.27% | — | E-plugins Directory PROAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Analizada | Baja (2.1) | 0.35% | — | Phpgurukul Directory Management System | 29/8/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly… | |
| Aplazada | Alta (8.1) | 0.33% | — | Emarketdesign Employee Directory Staff Listing Team DirectoryAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5. | |
| Analizada | Alta (7.5) | 1.4% | 💥 Exploit | Monospace Directus | 20/8/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident… | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Link DirectoryAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1. | |
| Aplazada | Alta (7.5) | 0.39% | — | Redirection FOR Contact Form 7AI | 20/8/2025 | 17/6/2026 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may… | |
| Aplazada | Alta (8.8) | 0.52% | — | Redirection FOR Contact Form 7AI | 20/8/2025 | 17/6/2026 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP… | |
| Aplazada | Alta (8.8) | 0.64% | — | Redirection FOR Contact Form 7AI | 20/8/2025 | 17/6/2026 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,… | |
| Aplazada | Alta (8.8) | 0.33% | — | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Crítica (9.8) | 0.37% | 💥 PoC | Real Spaces Wordpress Properties Directory ThemeAI | 19/8/2025 | 17/6/2026 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.17% | — | Cartpauj Shortcode RedirectAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode Redirect shortcode-redirect allows Stored XSS.This issue affects Shortcode Redirect: from n/a through <= 1.0.02. | |
| Analizada | Media (4.3) | 0.26% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users. | |
| Analizada | Media (5.4) | 0.24% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this. | |
| Analizada | Media (6.1) | 0.25% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data. | |
| Analizada | Media (5.3) | 0.29% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources. | |
| Analizada | Media (5.4) | 0.24% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access. | |
| Analizada | Media (6.1) | 0.34% | — | Netwrix Directory Manager | 7/8/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189. | |
| Aplazada | Media (6.4) | 0.25% | — | Employee DirectoryAI | 5/8/2025 | 17/6/2026 | The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.25% | — | Campus DirectoryAI | 5/8/2025 | 17/6/2026 | The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Alta (8.1) | 0.63% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key. | |
| Modificada | Media (4.3) | 0.82% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files. | |
| Modificada | Alta (8.8) | 2.1% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user. | |
| Modificada | Alta (8.8) | 1.8% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route. |