Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.34% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 stores passwords in a recoverable format. | |
| Modificada | Alta (8.8) | 0.98% | — | Commscope Ruckus Smartzone FirmwareCommscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | Ruckus SmartZone (SZ) before 6.1.2p3 Refresh Build allows authentication bypass via a valid API key and crafted HTTP headers. | |
| Modificada | Alta (8.8) | 0.48% | — | Commscope Ruckus Network Director | 4/8/2025 | 17/6/2026 | RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak, hardcoded password. | |
| Aplazada | Alta (7.5) | 0.45% | — | GeodirectoryAI | 26/7/2025 | 17/6/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Alta (7.2) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where the authenticated configuration endpoint `/admin/_conf.jsp` writes the Wi-Fi guest password to memory with snprintf using the attacker-supplied value as the format… | |
| Analizada | Crítica (9.1) | 1.1% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API endpoint `/admin/_cmdstat.jsp` passes attacker-controlled input to the shell without adequate validation, enabling a remote attacker to specify a target by MAC address and execute… | |
| Analizada | Crítica (9.8) | 1.3% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavourite` and `stamgr_cfg_adpt_addStaIot` pass a client hostname directly to snprintf as the format string. A remote attacker can exploit this flaw either by sending a crafted… | |
| Analizada | Crítica (9.8) | 1.00% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where a path-traversal flaw in the web interface lets the server execute attacker-supplied EJS templates outside permitted directories, allowing a remote unauthenticated… | |
| Analizada | Media (6.3) | 0.37% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282, where an authenticated request to the management endpoint `/admin/_cmdstat.jsp` discloses the administrator password in a trivially reversible obfuscated form. The same… | |
| Analizada | Media (5.3) | 0.53% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to 10.5.1.0.279, where hard-coded credentials for the ftpuser account provide FTP access to the controller, enabling a remote attacker to upload or retrieve arbitrary files from writable… | |
| Analizada | Crítica (9.1) | 0.83% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where a hidden debug script `.ap_debug.sh` invoked from the restricted CLI does not properly sanitize its input, allowing an authenticated attacker to execute arbitrary… | |
| Analizada | Alta (8.8) | 0.51% | — | Ruckuswireless Ruckus UnleashedRuckuswireless Ruckus Zonedirector | 21/7/2025 | 17/6/2026 | An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.1.0.279, where an authenticated attacker can disable the passphrase requirement for a hidden CLI command `!v54!` via a management API call and then invoke it to escape the… | |
| Aplazada | Media (5.1) | 0.36% | — | RsdirectoryAIJoomlaAI | 18/7/2025 | 17/6/2026 | A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component. | |
| Aplazada | Media (6.1) | 0.28% | — | Netwrix Directory ManagerAI | 17/7/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392. | |
| Aplazada | Crítica (9.3) | 0.38% | — | Cmsjunkie Wp-businessdirectoryAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Blind SQL Injection.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.4. | |
| Analizada | Media (6.5) | 0.44% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.9.0, Directus Flows with a manual trigger are not validating whether the user triggering the Flow has permissions to the items provided as payload to the Flow. Depending on what the Flow… | |
| Analizada | Media (5.3) | 0.98% | 💥 Exploit | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, the exact Directus version number is incorrectly being used as OpenAPI Spec version this means that it is being exposed by the `/server/specs/oas` endpoint without authentication.… | |
| Analizada | Media (4.5) | 0.43% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows with the WebHook trigger all incoming request details are logged including security sensitive data like access and refresh tokens in cookies. Malicious… | |
| Analizada | Media (4.2) | 0.19% | — | Monospace Directus | 15/7/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to version 11.9.0, when using Directus Flows to handle CRUD events for users it is possible to log the incoming data to console using the "Log to Console" operation and a template string. Malicious… | |
| Aplazada | Alta (8.7) | 0.39% | — | Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI | 14/7/2025 | 17/6/2026 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;… | |
| Aplazada | Alta (7.1) | 0.40% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1. | |
| Aplazada | Alta (8.7) | 1.1% | 💥 Exploit | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain… | |
| Analizada | Media (6.4) | 0.44% | — | Juniper Security Director | 11/7/2025 | 17/6/2026 | A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web interface. Numerous endpoints on the Juniper Security Director appliance do not validate authorization and will deliver… | |
| Modificada | Media (5.9) | 0.23% | — | Ayecode Geodirectory | 11/7/2025 | 17/6/2026 | The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.3) | 0.29% | — | Opentext Directory ServicesAI | 10/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4. |