Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.64% | — | WP Directorybox ManagerAI | 13/2/2025 | 17/6/2026 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an… | |
| Aplazada | Media (5.4) | 0.20% | — | Intel Thread Director VisualizerAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.33% | — | Adirectory | 12/2/2025 | 17/6/2026 | The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.4) | 0.44% | — | GeodirectoryAI | 11/2/2025 | 17/6/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.75% | 💥 PoC | WP Directorybox ManagerAI | 8/2/2025 | 17/6/2026 | The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user… | |
| Analizada | Alta (8.8) | 1.1% | — | IBM Security Verify Directory | 6/2/2025 | 17/6/2026 | IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Analizada | Media (5.3) | 0.41% | — | Wpwax Directorist | 1/2/2025 | 17/6/2026 | The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Security Verify Directory | 31/1/2025 | 17/6/2026 | IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themeglow Cleanup - Directory Listing AND ClassifiedsAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Media (6.5) | 0.18% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie… | |
| Analizada | Alta (7.5) | 0.32% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 27/1/2025 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the system. | |
| Aplazada | Media (6.5) | 0.57% | — | Connections-pro Connections Business DirectoryAI | 25/1/2025 | 17/6/2026 | The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all versions up to, and including, 10.4.66. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Alta (7.1) | 0.25% | — | Plestar Directory ListingAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hdw player Plestar Directory Listing plestar-directory-listing allows Reflected XSS.This issue affects Plestar Directory Listing: from n/a through <= 1.0. | |
| Analizada | Media (6.1) | 0.26% | — | Suhas93 SEO Blogger TO Wordpress 301 Redirector | 23/1/2025 | 17/6/2026 | The SEO Blogger to WordPress Migration using 301 Redirection plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 0.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.48% | — | Chandrika Guntur Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Chandrika Guntur, Morgan Kay Chamber Dashboard Business Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.8. | |
| Aplazada | Media (6.4) | 0.34% | — | Chamber Dashboard Business DirectoryAI | 16/1/2025 | 17/6/2026 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'business_categories' shortcode in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.1) | 0.29% | — | DWT Directory AND ListingAI | 16/1/2025 | 17/6/2026 | The DWT - Directory & Listing WordPress Theme is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping on the 'sort_by' and 'token' parameters. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Crítica (9.1) | 0.50% | — | Sonicwall Ssl-vpnAIMicrosoft Active DirectoryAI | 9/1/2025 | 17/6/2026 | SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal Name) and SAM (Security Account Manager) account names when integrated with Microsoft Active Directory, allowing MFA to be configured independently for each login method and potentially enabling… | |
| Modificada | Media (6.1) | 0.32% | — | Designinvento Directorypress | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows Reflected XSS.This issue affects DirectoryPress: from n/a through <= 3.6.19. | |
| Modificada | Media (5.4) | 0.33% | — | Ayecode Geodirectory | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.84. | |
| Aplazada | Media (4.3) | 0.26% | — | Dbar Productions Member Directory AND Contact FormAI | 31/12/2024 | 17/6/2026 | Missing Authorization vulnerability in DBAR Productions Member Directory and Contact Form pta-member-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Member Directory and Contact Form: from n/a through <= 1.7.0. | |
| Analizada | Media (5.4) | 0.30% | — | Designinvento Directorypress | 24/12/2024 | 17/6/2026 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.6.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.67% | — | IBM Security Directory Integrator | 20/12/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 through 7.2.0.13 and 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. |