Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.87% | — | Simple Phone Book/directory WEB APP Project Simple Phone Book/directory WEB APP | 7/12/2022 | 17/6/2026 | Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php. | |
| Modificada | Crítica (9.6) | 0.93% | — | Fusiondirectory | 22/11/2022 | 9/7/2026 | Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106. | |
| Modificada | Crítica (9.8) | 0.98% | — | Fusiondirectory | 22/11/2022 | 9/7/2026 | Fusiondirectory 1.3 suffers from Improper Session Handling. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Directory ServerRedhat Enterprise LinuxFedoraproject FedoraPort389 389-ds-base+1 | 14/10/2022 | 17/6/2026 | A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514. | |
| Modificada | Alta (7.5) | 0.52% | — | Ldap WP Login / Active Directory Integration Project Ldap WP Login / Active Directory Integration | 26/9/2022 | 17/6/2026 | The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated… | |
| Modificada | Alta (7.5) | 0.85% | — | Identity AND Directory Management System Project Identity AND Directory Management System | 21/9/2022 | 17/6/2026 | The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25 | |
| Modificada | Baja (3.9) | 0.25% | — | Okta Active Directory Agent | 6/9/2022 | 17/6/2026 | Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation. | |
| Modificada | Media (6.1) | 0.68% | — | Name Directory Project Name Directory | 25/7/2022 | 17/6/2026 | The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well | |
| Modificada | Media (6.1) | 0.33% | — | Name Directory Project Name Directory | 25/7/2022 | 17/6/2026 | The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them. | |
| Modificada | Crítica (9.8) | 1.7% | — | Phpgurukul Directory Management System | 16/6/2022 | 9/7/2026 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Phpgurukul Directory Management System | 16/6/2022 | 9/7/2026 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Phpgurukul Directory Management System | 16/6/2022 | 9/7/2026 | Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat 389 Directory ServerRedhat Directory ServerRedhat Enterprise LinuxFedoraproject Fedora | 2/6/2022 | 17/6/2026 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database… | |
| Modificada | Crítica (9.8) | 15% | — | Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System | 20/5/2022 | 17/6/2026 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Phpgurukul Directory Management System | 11/5/2022 | 17/6/2026 | Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication. | |
| Modificada | Crítica (9.8) | 1.6% | — | Medical HUB Directory Site Project Medical HUB Directory Site | 5/5/2022 | 17/6/2026 | Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System | 5/5/2022 | 17/6/2026 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat 389 Directory ServerFedoraproject FedoraRedhat Enterprise Linux | 23/3/2022 | 17/6/2026 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Quantumcloud Simple Link Directory | 21/3/2022 | 17/6/2026 | The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection | |
| Modificada | Media (6.5) | 0.45% | — | Jenkins Active Directory | 12/1/2022 | 17/6/2026 | Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations. | |
| Modificada | Media (6.5) | 3.3% | — | Microsoft Azure Active DirectoryMicrosoft Azure Active Site RecoveryMicrosoft Azure AutomationMicrosoft Azure Migrate | 24/11/2021 | 19/8/2026 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with… | |
| Modificada | Media (4.8) | 0.73% | — | Connections-pro Connections Business Directory | 1/11/2021 | 17/6/2026 | The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed. | |
| Modificada | Alta (8) | 1.2% | — | Connections-pro Connections Business Directory | 1/11/2021 | 17/6/2026 | The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue | |
| Modificada | Media (5.4) | 0.88% | — | Ayecode Geodirectory | 11/10/2021 | 17/6/2026 | The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). | |
| Modificada | Media (4.9) | 0.76% | — | Microfocus Netiq Directory AND Resource Administrator | 28/9/2021 | 17/6/2026 | Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure. |