Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 16/8/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and Security Verify Directory Integrator 10.0.0 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources, at the privilege level of a standard unprivileged user. IBM X-Force ID: 228570. | |
| Analizada | Media (6.3) | 0.58% | — | Opentext Directory Services | 12/8/2024 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | |
| Modificada | Alta (7.5) | 0.43% | — | IBM Security Directory IntegratorIBM Security Verify Directory Integrator | 30/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID:… | |
| Analizada | Media (6.8) | 0.50% | — | Salephpscripts WEB Directory Free | 30/7/2024 | 17/6/2026 | The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (8.3) | 0.57% | — | Opentext Directory ServicesAI | 26/7/2024 | 17/6/2026 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2. | |
| Modificada | Media (5.4) | 0.28% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Modificada | Alta (7.5) | 0.38% | — | IBM Security Directory IntegratorIBM Security Directory ServerIBM Security Verify Access | 25/7/2024 | 17/6/2026 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive information. IBM X-Force ID: 228565. | |
| Modificada | Alta (8.8) | 0.66% | — | Designinvento Directorypress | 22/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento DirectoryPress allows SQL Injection.This issue affects DirectoryPress: from n/a through 3.6.10. | |
| Modificada | Media (6.1) | 0.33% | — | Wpdirectorykit WP Directory KIT | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpdirectorykit.Com WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.3.5. | |
| Aplazada | Media (6.3) | 0.28% | — | Opentext Netiq Directory AND Resource AdministratorAI | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10. | |
| Modificada | Media (5.4) | 0.34% | — | Quantumcloud Simple Video Directory | 12/7/2024 | 17/6/2026 | The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.5) | 0.92% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/7/2024 | 17/6/2026 | A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of service. | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Analizada | Baja (2.7) | 0.32% | — | Wpdirectorykit WP Directory KIT | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP Directory Kit: from n/a through 1.3.6. | |
| Modificada | Media (5.4) | 0.33% | — | Vmware Cloud Director | 4/7/2024 | 17/6/2026 | VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks. | |
| Aplazada | Media (5.3) | 0.20% | — | Vmware Cloud Director Object Storage ExtensionAI | 27/6/2024 | 17/6/2026 | VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access to web/proxy server logging may be able to obtain sensitive information from URLs that are logged. | |
| Aplazada | Media (4.9) | 0.37% | — | Vmware Cloud DirectorAI | 27/6/2024 | 17/6/2026 | VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to accidentally disable their organization leading to a Denial of Service for active sessions within their own organization's scope. | |
| Modificada | Alta (8) | 0.49% | — | Businessdirectoryplugin Business Directory | 18/6/2024 | 17/6/2026 | The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can… | |
| Modificada | Media (5.4) | 0.31% | — | Businessdirectoryplugin Business Directory | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9. | |
| Modificada | Crítica (9.8) | 67% | 💥 Exploit | Salephpscripts WEB Directory Free | 13/6/2024 | 17/6/2026 | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Businessdirectoryplugin Business Directory | 22/5/2024 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Media (5.1) | 0.47% | — | Phpgurukul Directory Management System | 20/5/2024 | 17/6/2026 | A vulnerability classified as problematic was found in PHPGurukul Directory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php of the component Searchbar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.1) | 0.47% | — | Phpgurukul Directory Management System | 20/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Directory Management System 1.0. Affected is an unknown function of the file /admin/search-directory.php.. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.70% | — | Phpgurukul Directory Management System | 20/5/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.3) | 0.36% | — | Wpwax DirectoristAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6. |