Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1635 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5)0.25%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.
AnalizadaMedia (5.3)0.34%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
AnalizadaMedia (6.5)0.27%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.
AplazadaCrítica (9.8)0.49%—Quantumcloud Simple Business Directory PROAI23/5/202517/6/2026
Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9.
AplazadaMedia (4.3)0.23%—Jeroen Peters Name DirectoryAI19/5/202517/6/2026
Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= 1.30.0.
AnalizadaMedia (5.3)0.48%—Phpgurukul Directory Management System18/5/202517/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul Directory Management System 2.0. Affected by this issue is some unknown functionality of the file /searchdata.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be launched remotely. The…
AplazadaMedia (5.3)0.31%—Quantumcloud Simple Link DirectoryAI16/5/202517/6/2026
Missing Authorization vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Link Directory: from n/a through < 14.8.1.
AnalizadaCrítica (9.8)0.65%—Quantumcloud Simple Video Directory15/5/202517/6/2026
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AnalizadaMedia (6.9)0.51%—Phpgurukul Directory Management System15/5/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unknown part of the file /admin/forget-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.51%—Phpgurukul Directory Management System15/5/202517/6/2026
A vulnerability was found in PHPGurukul Directory Management System 2.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/edit-directory.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.22%—Phpgurukul Directory Management System30/4/202517/6/2026
A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.
AplazadaAlta (7.2)0.29%—Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI25/4/202517/6/2026
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and unauthorized modification of some software configuration parameters via undocumented user credentials. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
AplazadaCrítica (9.9)0.74%—Quantum StornextAIQuantum Stornext RYOAIQuantum Stornext Xcellis Workflow DirectorAIQuantum Activescale Cold StorageAI25/4/202517/6/2026
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
AplazadaMedia (5.3)0.40%—Prevent Direct Access Protect Wordpress FilesAI25/4/202517/6/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to…
AplazadaMedia (5.4)0.29%—Prevent Direct AccessAI25/4/202517/6/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with…
AnalizadaMedia (6.5)0.33%—IBM Sterling Connect Direct WEB Services18/4/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 could allow an authenticated user to spoof the identity of another user due to improper authorization which could allow the user to bypass access restrictions.
AnalizadaMedia (6.5)0.31%—IBM Sterling Connect Direct WEB Services18/4/202517/6/2026
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
AplazadaAlta (7.1)0.23%—Salephpscripts WEB Directory FreeAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8.
AplazadaAlta (7.1)0.15%—Eslam Mahmoud Redirect Wordpress TO Welcome OR Landing PageAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-to-welcome-or-landing-page allows Stored XSS.This issue affects Redirect wordpress to welcome or landing page: from n/a through <= 2.0.
AplazadaAlta (7.1)0.29%—Cmsjunkie Wp-businessdirectoryAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Reflected XSS.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2.
AplazadaAlta (8.6)0.78%—Cmsjunkie WP BusinessdirectoryAI11/4/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CMSJunkie - WordPress Business Directory Plugins WP-BusinessDirectory wp-businessdirectory allows Path Traversal.This issue affects WP-BusinessDirectory: from n/a through <= 3.1.2.
AplazadaMedia (5.3)0.62%—FusiondirectoryAI11/4/202517/6/2026
A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.
AplazadaMedia (4.3)0.19%—Wp-buy 404 Image Redirection Replace Broken ImagesAI4/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy 404 Image Redirection (Replace Broken Images) broken-images-redirection allows Cross Site Request Forgery.This issue affects 404 Image Redirection (Replace Broken Images): from n/a through <= 1.4.
AplazadaMedia (5.4)0.22%—Designinvento DirectorypressAI4/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Designinvento DirectoryPress directorypress allows Cross Site Request Forgery.This issue affects DirectoryPress: from n/a through <= 3.6.22.
AplazadaMedia (6.5)0.40%—Morgan KAY Chamber Dashboard Business DirectoryAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Morgan Kay Chamber Dashboard Business Directory allows DOM-Based XSS. This issue affects Chamber Dashboard Business Directory: from n/a through 3.3.11.
Orbitaley — Vulnerabilidades