Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.87%—Simple Phone Book/directory WEB APP Project Simple Phone Book/directory WEB APP7/12/202217/6/2026
Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.
ModificadaCrítica (9.6)0.93%—Fusiondirectory22/11/20229/7/2026
Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.
ModificadaCrítica (9.8)0.98%—Fusiondirectory22/11/20229/7/2026
Fusiondirectory 1.3 suffers from Improper Session Handling.
ModificadaMedia (6.5)1.3%—Redhat Directory ServerRedhat Enterprise LinuxFedoraproject FedoraPort389 389-ds-base+114/10/202217/6/2026
A flaw was found In 389-ds-base. When the Content Synchronization plugin is enabled, an authenticated user can reach a NULL pointer dereference using a specially crafted query. This flaw allows an authenticated attacker to cause a denial of service. This CVE is assigned against an incomplete fix of CVE-2021-3514.
ModificadaAlta (7.5)0.52%—Ldap WP Login / Active Directory Integration Project Ldap WP Login / Active Directory Integration26/9/202217/6/2026
The Ldap WP Login / Active Directory Integration WordPress plugin before 3.0.2 does not have any authorisation and CSRF checks when updating it's settings (which are hooked to the init action), allowing unauthenticated attackers to update them. Attackers could set their own LDAP server to be used to authenticated…
ModificadaAlta (7.5)0.85%—Identity AND Directory Management System Project Identity AND Directory Management System21/9/202217/6/2026
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25
ModificadaBaja (3.9)0.25%—Okta Active Directory Agent6/9/202217/6/2026
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted path. Note: To remediate this vulnerability, you must uninstall Okta Active Directory Agent and reinstall Okta Active Directory Agent 3.12.0 or greater per the documentation.
ModificadaMedia (6.1)0.68%—Name Directory Project Name Directory25/7/202217/6/2026
The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well
ModificadaMedia (6.1)0.33%—Name Directory Project Name Directory25/7/202217/6/2026
The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
ModificadaCrítica (9.8)1.7%—Phpgurukul Directory Management System16/6/20229/7/2026
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
ModificadaCrítica (9.8)1.7%—Phpgurukul Directory Management System16/6/20229/7/2026
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
ModificadaCrítica (9.8)1.7%—Phpgurukul Directory Management System16/6/20229/7/2026
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.
ModificadaAlta (7.5)1.5%—Redhat 389 Directory ServerRedhat Directory ServerRedhat Enterprise LinuxFedoraproject Fedora2/6/202217/6/2026
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any remote unauthenticated user to issue a filter that allows searching for database…
ModificadaCrítica (9.8)15%—Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System20/5/202217/6/2026
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.
ModificadaCrítica (9.8)19%💥 ExploitPhpgurukul Directory Management System11/5/202217/6/2026
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
ModificadaCrítica (9.8)1.6%—Medical HUB Directory Site Project Medical HUB Directory Site5/5/202217/6/2026
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
ModificadaCrítica (9.8)1.6%—Covid-19 Directory ON Vaccination System Project Covid-19 Directory ON Vaccination System5/5/202217/6/2026
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
ModificadaMedia (6.5)1.5%—Redhat 389 Directory ServerFedoraproject FedoraRedhat Enterprise Linux23/3/202217/6/2026
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
ModificadaCrítica (9.8)11%💥 ExploitQuantumcloud Simple Link Directory21/3/202217/6/2026
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX action (available to unauthenticated and authenticated users), leading to an unauthenticated SQL Injection
ModificadaMedia (6.5)0.45%—Jenkins Active Directory12/1/202217/6/2026
Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controller and Active Directory servers in most configurations.
ModificadaMedia (6.5)3.3%—Microsoft Azure Active DirectoryMicrosoft Azure Active Site RecoveryMicrosoft Azure AutomationMicrosoft Azure Migrate24/11/202119/8/2026
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with…
ModificadaMedia (4.8)0.73%—Connections-pro Connections Business Directory1/11/202117/6/2026
The Connections Business Directory WordPress plugin before 10.4.3 does not escape the Address settings when creating an Entry, which could allow high privilege users to perform Cross-Site Scripting when the unfiltered_html capability is disallowed.
ModificadaAlta (8)1.2%—Connections-pro Connections Business Directory1/11/202117/6/2026
The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue
ModificadaMedia (5.4)0.88%—Ayecode Geodirectory11/10/202117/6/2026
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
ModificadaMedia (4.9)0.76%—Microfocus Netiq Directory AND Resource Administrator28/9/202117/6/2026
Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.
Orbitaley — Vulnerabilidades