Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.74% | — | Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI | 25/4/2025 | 17/6/2026 | Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage. | |
| Aplazada | Alta (7.1) | 0.23% | — | Salephpscripts WEB Directory FreeAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8. | |
| Aplazada | Alta (7.1) | 0.29% | — | Cmsjunkie Wp-businessdirectoryAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Reflected XSS.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2. | |
| Aplazada | Alta (8.6) | 0.78% | — | Cmsjunkie WP BusinessdirectoryAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Path Traversal.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2. | |
| Aplazada | Media (5.3) | 0.62% | — | FusiondirectoryAI | 11/4/2025 | 17/6/2026 | A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Designinvento DirectorypressAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22. | |
| Aplazada | Media (6.5) | 0.40% | — | Morgan KAY Chamber Dashboard Business DirectoryAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11. | |
| Aplazada | Alta (7.1) | 0.15% | — | Salephpscripts WEB Directory FreeAI | 3/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free web-directory-free allows Stored XSS.This issue affects Web Directory Free: from n/a through <= 1.7.6. | |
| Aplazada | Media (6.4) | 0.31% | — | BIG Boom DirectoryAI | 3/4/2025 | 17/6/2026 | The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpwax Directorist Addonskit FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Directorist AddonsKit for Elementor addonskit-for-elementor allows Stored XSS.This issue affects Directorist AddonsKit for Elementor: from n/a through <= 1.1.6. | |
| Aplazada | Media (5.5) | 0.40% | — | Icinga DirectorAI | 26/3/2025 | 17/6/2026 | Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Salephpscripts WEB Directory FreeAI | 25/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free allows Blind SQL Injection.This issue affects Web Directory Free: from n/a through <= 1.7.6. | |
| Aplazada | Media (5.3) | 0.41% | — | Wpwax DirectoristAI | 25/3/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.8) | 0.22% | — | Foodbakery Delivery Restaurant DirectoryAI | 19/3/2025 | 17/6/2026 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save,… | |
| Aplazada | Media (5.3) | 0.27% | — | Businessdirectoryplugin Business Directory PluginAI | 13/3/2025 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.14 via the 'ajax_listing_submit_image_upload' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (8.7) | 0.52% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 12/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before… | |
| Aplazada | Media (6.1) | 0.35% | — | Goldplugins Staff Directory PluginAI | 5/3/2025 | 17/6/2026 | The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Alta (8.6) | 94% | ⚠ Explotación activa💥 Exploit | Nakivo Backup & Replication Director | 4/3/2025 | 24/9/2026 | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials). | |
| Modificada | Alta (8.8) | 0.69% | — | Wpgeodirectory Events Calendar* | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14. | |
| Aplazada | Alta (7.1) | 0.39% | — | Goldplugins Staff Directory PluginAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richardgabriel Staff Directory Plugin: Company Directory staff-directory-pro allows Stored XSS.This issue affects Staff Directory Plugin: Company Directory: from n/a through <= 4.3. | |
| Analizada | Crítica (9.8) | 0.44% | — | Wpwax Directorist | 28/2/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having… | |
| Analizada | Baja (3.3) | 0.15% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 22/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.14% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 21/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user. | |
| Analizada | Media (4.3) | 0.17% | — | Designinvento Directorypress | 15/2/2025 | 17/6/2026 | The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing or incorrect nonce validation on the dpfl_listingStatusChange() function. This makes it possible for unauthenticated attackers to update listing statuses via… | |
| Aplazada | Crítica (9.8) | 0.90% | — | Alvaria Unified IP Unified DirectorAI | 14/2/2025 | 17/6/2026 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component. |