Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.29% | — | Quantumcloud Simple Link DirectoryAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows SQL Injection.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Aplazada | Media (5) | 0.16% | — | Oneidentity Onelogin Active Directory ConnectorAI | 2/7/2025 | 17/6/2026 | In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812. | |
| Aplazada | Crítica (9.3) | 0.32% | — | Directiq Email MarketingAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DirectIQ DirectIQ Email Marketing directiq-wp allows SQL Injection.This issue affects DirectIQ Email Marketing: from n/a through <= 2.0. | |
| Aplazada | Media (5.9) | 0.26% | — | Robert Peake Better Random RedirectAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robert Peake Better Random Redirect better-random-redirect allows Stored XSS.This issue affects Better Random Redirect: from n/a through <= 1.3.20. | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /admin/manage-directory.php. The manipulation of the argument del leads to sql injection. The attack may be launched remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search-directory.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.49% | — | Phpgurukul Directory Management System | 20/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /searchdata.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.1) | 0.38% | — | Versa-networks Versa Director | 19/6/2025 | 8/9/2026 | The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of… | |
| Analizada | Crítica (9.8) | 0.47% | — | Versa-networks Versa Director | 19/6/2025 | 2/9/2026 | The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Versa director exposes ssh and postgres to the internet, alongside a host of other… | |
| Analizada | Alta (7.5) | 0.62% | — | Versa-networks Versa Director | 19/6/2025 | 8/9/2026 | The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weaknesses that can be… | |
| Analizada | Alta (7.2) | 1.1% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to execute commands on… | |
| Analizada | Alta (7.2) | 0.55% | — | Versa-networks Versa Director | 19/6/2025 | 25/8/2026 | The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to allow file uploads but uploads still succeed. In addition, the Versa Director discloses the full filename of uploaded… | |
| Analizada | Media (6.7) | 0.59% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands… | |
| Analizada | Media (6.1) | 0.38% | — | Versa-networks Versa Director | 19/6/2025 | 3/9/2026 | The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) payloads.… | |
| Analizada | Alta (8.8) | 0.40% | — | Versa-networks Versa Director | 19/6/2025 | 17/6/2026 | The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and password to redirect the OTP delivery… | |
| Aplazada | Crítica (9.8) | 0.86% | — | Cisco NCSAIVersa-networks Versa DirectorAI | 19/6/2025 | 17/6/2026 | The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Directors communicate over TCP ports 4566 and 4570 to exchange High Availability (HA) information using a shared password. Affected versions of Versa Director bound to these ports on all interfaces. An… | |
| Analizada | Alta (7.8) | 0.17% | — | IBM Security Verify Directory | 15/6/2025 | 17/6/2026 | IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges. | |
| Analizada | Alta (8.8) | 0.33% | — | Commerce Alphabank Redirect Project Commerce Alphabank Redirect | 11/6/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Commerce Alphabank Redirect allows Functionality Misuse.This issue affects Commerce Alphabank Redirect: from 0.0.0 before 1.0.3. | |
| Analizada | Alta (8.8) | 0.32% | — | Commerce Eurobank (redirect) Project Commerce Eurobank (redirect) | 11/6/2025 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Commerce Eurobank (Redirect) allows Functionality Misuse.This issue affects Commerce Eurobank (Redirect): from 0.0.0 before 2.1.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Centangle WOO Direct Checkout LiteAI | 6/6/2025 | 17/6/2026 | Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3. | |
| Aplazada | Media (6.4) | 0.22% | — | Campus DirectoryAI | 4/6/2025 | 17/6/2026 | The Campus Directory – Faculty, Staff & Student Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (6.4) | 0.22% | — | Employee DirectoryAI | 4/6/2025 | 17/6/2026 | The Employee Directory – Staff Listing & Team Directory Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'emd_mb_meta' shortcode in all versions up to, and including, 4.5.0 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Analizada | Crítica (10) | 0.40% | — | Netwrix Directory Manager | 29/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password. | |
| Analizada | Crítica (9.1) | 0.43% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data. |