Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.18%—Sonicwall Directory Services Connector27/10/202317/6/2026
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.
ModificadaMedia (6.1)0.33%—Lava-code Lava Directory Manager26/10/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
ModificadaAlta (7.5)26%💥 ExploitMiniorange Active Directory Integration / Ldap Integration16/10/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
ModificadaAlta (7.5)1.5%—IBM Security Directory Integrator14/10/202317/6/2026
IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.
ModificadaMedia (5.9)0.55%—IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Directory SuiteIBM Security Verify Directory14/10/202317/6/2026
IBM Security Directory Server 6.4.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. X-Force ID: 228569.
ModificadaCrítica (9.1)0.91%—IBM Security Directory ServerIBM Security Directory SuiteIBM Security Verify Directory14/10/202317/6/2026
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 228505.
ModificadaAlta (7.5)0.32%—IBM Security Directory Suite VA6/10/202317/6/2026
IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228568.
ModificadaMedia (6.5)0.91%—Miniorange Active Directory Integration / Ldap Integration27/9/202317/6/2026
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 4.1.10. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the…
ModificadaMedia (4.9)0.91%—Miniorange Staff / Employee Business Directory FOR Active Directory27/9/202317/6/2026
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to…
ModificadaCrítica (9.1)1.5%—IBM Security Directory Server8/9/202317/6/2026
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view or write to arbitrary files on the system. IBM X-Force ID: 228579.
ModificadaMedia (6.1)1.0%💥 ExploitAjaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+424/9/202317/6/2026
All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite…
ModificadaMedia (5.4)0.29%—Wpdirectorykit WP Directory KIT31/8/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the 'admin_page_display' function. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo…
ModificadaAlta (7.5)0.67%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
ModificadaMedia (6.1)0.43%—Phpjabbers Business Directory Script30/8/202317/6/2026
phpjabbers Business Directory Script 3.2 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
ModificadaMedia (4.8)0.37%—Icontrolwp Article Directory Redux14/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in iControlWP Article Directory Redux plugin <= 1.0.2 versions.
ModificadaMedia (6.1)0.39%—Bugfinder Listplace Directory Listing Platform22/7/202317/6/2026
A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic. This affects an unknown part of the file /listplace/user/coverPhotoUpdate of the component Photo Handler. The manipulation of the argument user_cover_photo leads to cross site scripting. It is…
ModificadaMedia (6.1)0.39%—Bugfinder Listplace Directory Listing Platform22/7/202317/6/2026
A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /listplace/user/ticket/create of the component HTTP POST Request Handler. The manipulation of the argument message leads to cross site…
ModificadaMedia (5.9)0.46%—Jenkins Active Directory12/7/202317/6/2026
Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing attackers able to capture network traffic between the Jenkins controller and Active Directory servers to obtain Active Directory…
ModificadaMedia (4.3)0.39%—Goldplugins Staff Directory Plugin1/7/202317/6/2026
The Staff Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6. This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request…
ModificadaAlta (7.5)0.53%—Miniorange Active Directory Integration / Ldap Integration29/6/202317/6/2026
The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up to, and including, 4.1.5. This is due to insufficient escaping on the supplied username value. This makes it possible for attackers, with an existing account on a vulnerable WordPress instance, to…
ModificadaMedia (5.4)0.37%—Connections-pro Connections Business Directory26/6/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Steven A. Zahm Connections Business Directory plugin <= 10.4.36 versions.
ModificadaAlta (7.2)0.79%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 228586.
ModificadaAlta (7.5)0.85%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 228510.
ModificadaAlta (8.8)1.4%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 228439.
ModificadaAlta (7.5)0.77%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA 8.0.1 could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 228588.
Orbitaley — Vulnerabilidades