Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.50% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA 8.0.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 228571. | |
| Modificada | Media (6.5) | 0.34% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 228567. | |
| Modificada | Media (4.3) | 0.64% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete… | |
| Modificada | Crítica (9.8) | 1.7% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be… | |
| Modificada | Media (4.7) | 0.34% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious… | |
| Modificada | Media (6.5) | 0.42% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied… | |
| Modificada | Media (4.9) | 0.85% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Media (5.3) | 0.60% | — | Wpdirectorykit WP Directory KIT | 9/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo… | |
| Modificada | Media (6.1) | 0.72% | — | Wpdirectorykit WP Directory KIT | 2/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (8.8) | 0.81% | — | Salephpscripts WEB Directory Free | 2/6/2023 | 17/6/2026 | The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.27% | — | Name Directory Project Name Directory | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions. | |
| Modificada | Media (4.3) | 0.30% | — | Jenkins Lightweight Directory Access Protocol | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. | |
| Modificada | Alta (7.5) | 0.82% | — | Miniorange Active Directory Integration / Ldap Integration | 15/5/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure. | |
| Modificada | Alta (7.8) | 0.33% | — | Nokia One-network Directory Server | 25/4/2023 | 17/6/2026 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. | |
| Modificada | Media (4.8) | 0.47% | — | Article Directory Project Article Directory | 10/4/2023 | 17/6/2026 | The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts. | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (6.1) | 0.56% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to… | |
| Modificada | Media (6.1) | 0.59% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. Affected is an unknown function of the file verification.php. The manipulation of the argument txtvaccinationID leads to cross site scripting. It is possible to… | |
| Modificada | Alta (8.1) | 0.86% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The… | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Directory ServerFedoraproject Fedora | 27/2/2023 | 17/6/2026 | A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed… | |
| Modificada | Alta (7.2) | 0.76% | — | Wpgeodirectory Geodirectory | 27/2/2023 | 17/6/2026 | The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Media (5.4) | 0.47% | — | Ayecode Geodirectory | 23/1/2023 | 17/6/2026 | The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Alta (7.5) | 0.56% | — | Miniorange Ldap Integration With Active Directory AND Openldap | 17/1/2023 | 17/6/2026 | The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database. | |
| Modificada | Media (6.1) | 0.55% | — | Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System | 21/12/2022 | 17/6/2026 | A Cross site scripting (XSS) vulnerability in Sourcecodester Online Covid-19 Directory on Vaccination System v1.0 allows attackers to execute arbitrary code via the txtfullname parameter or txtphone parameter to register.php without logging in. | |
| Modificada | Media (6.1) | 0.49% | — | Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System | 21/12/2022 | 17/6/2026 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulnerability via verification.php because the program does not verify the txtvaccinationID parameter. |