Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.25% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource. | |
| Analizada | Media (5.3) | 0.34% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password. | |
| Analizada | Media (6.5) | 0.27% | — | Netwrix Directory Manager | 28/5/2025 | 17/6/2026 | Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Media (4.3) | 0.23% | — | Jeroen Peters Name DirectoryAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0. | |
| Analizada | Media (5.3) | 0.48% | — | Phpgurukul Directory Management System | 18/5/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Media (5.3) | 0.31% | — | Quantumcloud Simple Link DirectoryAI | 16/5/2025 | 17/6/2026 | Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1. | |
| Analizada | Crítica (9.8) | 0.65% | — | Quantumcloud Simple Video Directory | 15/5/2025 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Directory Management System | 15/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/forget-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.51% | — | Phpgurukul Directory Management System | 15/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-directory.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.22% | — | Phpgurukul Directory Management System | 30/4/2025 | 17/6/2026 | A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands. | |
| Aplazada | Alta (7.2) | 0.29% | — | Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI | 25/4/2025 | 17/6/2026 | Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage. | |
| Aplazada | Crítica (9.9) | 0.74% | — | Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI | 25/4/2025 | 17/6/2026 | Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage. | |
| Aplazada | Media (5.3) | 0.40% | — | Prevent Direct Access Protect Wordpress FilesAI | 25/4/2025 | 17/6/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (5.4) | 0.29% | — | Prevent Direct AccessAI | 25/4/2025 | 17/6/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Sterling Connect Direct WEB Services | 18/4/2025 | 17/6/2026 | IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Alta (7.1) | 0.23% | — | Salephpscripts WEB Directory FreeAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8. | |
| Aplazada | Alta (7.1) | 0.15% | — | Eslam Mahmoud Redirect Wordpress TO Welcome OR Landing PageAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-to-welcome-or-landing-page allows Stored XSS.This issue affects Redirect wordpress to welcome or landing page: from n/a through <= 2.0. | |
| Aplazada | Alta (7.1) | 0.29% | — | Cmsjunkie Wp-businessdirectoryAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Reflected XSS.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2. | |
| Aplazada | Alta (8.6) | 0.78% | — | Cmsjunkie WP BusinessdirectoryAI | 11/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Path Traversal.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2. | |
| Aplazada | Media (5.3) | 0.62% | — | FusiondirectoryAI | 11/4/2025 | 17/6/2026 | A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php. | |
| Aplazada | Media (4.3) | 0.19% | — | Wp-buy 404 Image Redirection Replace Broken ImagesAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wp-buy 404 Image Redirection (Replace Broken Images) broken-images-redirection allows Cross Site Request Forgery.This issue affects 404 Image Redirection (Replace Broken Images): from n/a through <= 1.4. | |
| Aplazada | Media (5.4) | 0.22% | — | Designinvento DirectorypressAI | 4/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22. | |
| Aplazada | Media (6.5) | 0.40% | — | Morgan KAY Chamber Dashboard Business DirectoryAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11. |