Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.44% | — | LDD WEB Design LDD Directory LiteAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LDD Web Design LDD Directory Lite ldd-directory-lite allows Reflected XSS.This issue affects LDD Directory Lite: from n/a through <= 3.3. | |
| Modificada | Crítica (9.8) | 0.79% | — | Wpdirectorykit WP Directory KIT | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through 1.2.6. | |
| Modificada | Crítica (9.8) | 0.73% | — | Designinvento Directorypress | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Designinvento DirectoryPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through 3.6.2. | |
| Aplazada | Media (4.3) | 0.39% | — | Wpwax DirectoristAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4. | |
| Aplazada | Media (6.5) | 0.48% | — | Quantumcloud Simple Link DirectoryAI | 13/12/2024 | 17/6/2026 | The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.4.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.38% | — | Wpdirectorykit Real Estate DirectoryAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wpdirectorykit.com Real Estate Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Directory: from n/a through 1.0.5. | |
| Analizada | Crítica (10) | 0.58% | — | Versa-networks Versa Director | 19/11/2024 | 3/9/2026 | The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Availability function of the Versa Director. The default configuration has a common password across all instances of Versa Director. By default, Versa Director configures Postgres to listen on all… | |
| Analizada | Media (5.5) | 0.20% | — | Cisco Industrial Network Director | 15/11/2024 | 17/6/2026 | A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. | |
| Analizada | Crítica (9.9) | 14% | — | Cisco Industrial Network Director | 15/11/2024 | 17/6/2026 | A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying operating system of an affected device. This vulnerability is due to improper input validation when uploading a Device Pack. An attacker could exploit… | |
| Aplazada | Crítica (10) | 1.5% | 💥 PoC | Joshua Wolfe THE Novel Design Store DirectoryAI | 11/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0. | |
| Analizada | Alta (8.8) | 0.42% | — | Ayecode Geodirectory | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70. | |
| Aplazada | Crítica (10) | 0.51% | — | AdirectoryAI | 29/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in aDirectory aDirectory adirectory allows Upload a Web Shell to a Web Server.This issue affects aDirectory: from n/a through <= 1.3. | |
| Modificada | Media (5.4) | 0.26% | — | Ayecode Geodirectory | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.80. | |
| Aplazada | Alta (7.1) | 0.32% | — | Salephpscripts WEB Directory FreeAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.3. | |
| Analizada | Media (6.6) | 0.51% | — | Versa-networks Versa Director | 20/9/2024 | 25/8/2026 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen, banner display, and device registration, do not require authentication. However, it was discovered that for Directors directly connected to the Internet, one of these APIs can be exploited by… | |
| Aplazada | Media (6.5) | 0.26% | — | Jeroen Peters Name DirectoryAI | 17/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.29.0. | |
| Analizada | Media (6.5) | 0.35% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | |
| Analizada | Crítica (9.8) | 0.40% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000. | |
| Analizada | Media (6.1) | 0.24% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000. | |
| Analizada | Crítica (9.1) | 0.44% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000. | |
| Analizada | Alta (7.5) | 0.37% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000. | |
| Analizada | Media (6.1) | 0.24% | — | Microfocus Edirectory | 12/9/2024 | 17/6/2026 | Possible Improper Neutralization of Input During Web Page Generation Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.3.0000. | |
| Analizada | Crítica (9.1) | 5.6% | 💥 Exploit | Salephpscripts WEB Directory Free | 30/8/2024 | 17/6/2026 | The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues. | |
| Analizada | Alta (7.2) | 4.0% | ⚠ Explotación activa | Versa-networks Versa Director | 22/8/2024 | 17/6/2026 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user logged with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin. (Tenant level users do not have this privilege). The “Change Favicon” (Favorite Icon) option can be… | |
| Analizada | Alta (8.8) | 0.44% | — | Ayecode Geodirectory | 18/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61. |