Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1635 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.27%—E-plugins Directory PROAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5.
AnalizadaBaja (2.1)0.35%—Phpgurukul Directory Management System29/8/202517/6/2026
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly…
AplazadaAlta (8.1)0.33%—Emarketdesign Employee Directory Staff Listing Team DirectoryAI28/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in emarket-design Employee Directory – Staff Listing & Team Directory Plugin for WordPress employee-directory allows Object Injection.This issue affects Employee Directory – Staff Listing & Team Directory Plugin for WordPress: from n/a through <= 4.5.5.
AnalizadaAlta (7.5)1.4%💥 ExploitMonospace Directus20/8/202517/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being applied to the files' database-resident…
AplazadaCrítica (9.8)0.37%💥 PoCQuantumcloud Simple Business Directory PROAI20/8/202517/6/2026
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
AplazadaAlta (7.1)0.23%—Quantumcloud Simple Link DirectoryAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Reflected XSS.This issue affects Simple Link Directory: from n/a through < 14.8.1.
AplazadaAlta (7.1)0.23%—Quantumcloud Simple Business Directory PROAI20/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1.
AplazadaAlta (7.5)0.39%—Redirection FOR Contact Form 7AI20/8/202517/6/2026
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the delete_associated_files function. This makes it possible for unauthenticated attackers to inject a PHP Object. This vulnerability may…
AplazadaAlta (8.8)0.52%—Redirection FOR Contact Form 7AI20/8/202517/6/2026
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.4 via deserialization of untrusted input in the get_lead_fields function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP…
AplazadaAlta (8.8)0.64%—Redirection FOR Contact Form 7AI20/8/202517/6/2026
The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_associated_files function in all versions up to, and including, 3.2.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server,…
AplazadaAlta (8.8)0.33%—Real Spaces Wordpress Properties Directory ThemeAI19/8/202517/6/2026
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'change_role_member' parameter in all versions up to, and including, 3.5. This is due to a lack of restriction in the profile update role. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.37%💥 PoCReal Spaces Wordpress Properties Directory ThemeAI19/8/202517/6/2026
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This is due to a lack of restriction in the registration role. This makes it possible for unauthenticated attackers to…
AplazadaMedia (6.5)0.17%—Cartpauj Shortcode RedirectAI14/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode Redirect shortcode-redirect allows Stored XSS.This issue affects Shortcode Redirect: from n/a through <= 1.0.02.
AnalizadaMedia (4.3)0.26%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.
AnalizadaMedia (6.1)0.25%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
AnalizadaMedia (5.3)0.29%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.
AnalizadaMedia (6.1)0.34%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
AplazadaMedia (6.4)0.25%—Employee DirectoryAI5/8/202517/6/2026
The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (6.4)0.25%—Campus DirectoryAI5/8/202517/6/2026
The Campus Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to…
ModificadaAlta (8.1)0.63%—Commscope Ruckus Network Director4/8/202517/6/2026
RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.
ModificadaMedia (4.3)0.82%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows ../ directory traversal to read files.
ModificadaAlta (8.8)2.1%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.
ModificadaAlta (8.8)1.8%—Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director4/8/202517/6/2026
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
Orbitaley — Vulnerabilidades