Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Automationdirect C-more ViewjetAI | 4/4/2025 | 17/6/2026 | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. | |
| Aplazada | Media (5.8) | 0.46% | — | Automationdirect Viewjet C-moreAIAutomationdirect Gc-a2AI | 4/4/2025 | 17/6/2026 | Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack. | |
| Aplazada | Alta (7.1) | 0.15% | — | Salephpscripts WEB Directory FreeAI | 3/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free web-directory-free allows Stored XSS.This issue affects Web Directory Free: from n/a through <= 1.7.6. | |
| Aplazada | Media (6.4) | 0.31% | — | BIG Boom DirectoryAI | 3/4/2025 | 17/6/2026 | The Big Boom Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bbd-search' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpwax Directorist Addonskit FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Directorist AddonsKit for Elementor addonskit-for-elementor allows Stored XSS.This issue affects Directorist AddonsKit for Elementor: from n/a through <= 1.1.6. | |
| Analizada | Alta (7.5) | 0.52% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to version 11.5.0, when a Flow with the "Webhook" trigger and the "Data of Last Operation" response body encounters a ValidationError thrown by a failed condition operation, the API response includes… | |
| Analizada | Media (5.3) | 0.37% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0-alpha.4 and prior to version 11.5.0, the `search` query parameter allows users with access to a collection to filter items based on fields they do not have permission to view. This allows the enumeration of… | |
| Analizada | Media (4.3) | 0.37% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 10.10.0 and prior to version 11.5.0, a suspended user can use the token generated in session auth mode to access the API despite their status. This happens because there is a check missing in `verifySessionJWT` to… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of HEAD… | |
| Analizada | Media (5.3) | 0.43% | — | Monospace Directus | 26/3/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. The `@directus/storage-driver-s3` package starting in version 9.22.0 and prior to version 12.0.1, corresponding to Directus starting in version 9.22.0 and prior to 11.5.0, is vulnerable to asset unavailability after a burst of malformed… | |
| Aplazada | Alta (7.1) | 0.31% | — | Hectorgarrofe Driving DirectionsAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hectorgarrofe Driving Directions ddirections allows Reflected XSS.This issue affects Driving Directions: from n/a through <= 1.4.4. | |
| Aplazada | Media (5.5) | 0.40% | — | Icinga DirectorAI | 26/3/2025 | 17/6/2026 | Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Salephpscripts WEB Directory FreeAI | 25/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free allows Blind SQL Injection.This issue affects Web Directory Free: from n/a through <= 1.7.6. | |
| Aplazada | Media (5.3) | 0.41% | — | Wpwax DirectoristAI | 25/3/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.9) | 0.35% | — | Arefly Login-redirectAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arefly Login Redirect login-redirect allows Stored XSS.This issue affects Login Redirect: from n/a through <= 1.0.5. | |
| Aplazada | Media (4.3) | 0.21% | — | Odihost Easy 301 RedirectsAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects odihost-easy-redirect-301 allows Cross Site Request Forgery.This issue affects Easy 301 Redirects: from n/a through <= 1.33. | |
| Aplazada | Alta (8.8) | 0.22% | — | Foodbakery Delivery Restaurant DirectoryAI | 19/3/2025 | 17/6/2026 | The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7. This is due to missing or incorrect nonce validation on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save,… | |
| Aplazada | Media (5.3) | 0.27% | — | Businessdirectoryplugin Business Directory PluginAI | 13/3/2025 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.14 via the 'ajax_listing_submit_image_upload' function due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Alta (8.7) | 0.52% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 12/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before… | |
| Aplazada | Media (6.1) | 0.35% | — | Goldplugins Staff Directory PluginAI | 5/3/2025 | 17/6/2026 | The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Alta (8.6) | 94% | ⚠ Explotación activa💥 Exploit | Nakivo Backup & Replication Director | 4/3/2025 | 24/9/2026 | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials). | |
| Modificada | Alta (8.8) | 0.69% | — | Wpgeodirectory Events Calendar* | 3/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14. | |
| Aplazada | Alta (7.1) | 0.39% | — | Goldplugins Staff Directory PluginAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richardgabriel Staff Directory Plugin: Company Directory staff-directory-pro allows Stored XSS.This issue affects Staff Directory Plugin: Company Directory: from n/a through <= 4.3. | |
| Aplazada | Alta (7.1) | 0.39% | — | Robin90 First Comment RedirectAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robin90 First Comment Redirect first-comment-redirect allows Reflected XSS.This issue affects First Comment Redirect: from n/a through <= 1.0.3. | |
| Aplazada | Media (5.3) | 0.30% | — | Ip2location RedirectionAI | 1/3/2025 | 17/6/2026 | The IP2Location Redirection plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'download_ip2location_redirection_backup' AJAX action in all versions up to, and including, 1.33.3. This makes it possible for unauthenticated attackers to download the plugin's… |