Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.32% | — | Ayecode Geodirectory | 23/4/2024 | 17/6/2026 | The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_single_tabs' shortcode in all versions up to, and including, 2.3.48 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (6.1) | 0.37% | — | Designinvento Directorypress | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress allows Reflected XSS.This issue affects DirectoryPress: from n/a through 3.6.7. | |
| Aplazada | Media (4.3) | 0.54% | — | Advanced Classifieds Directory PROAI | 9/4/2024 | 17/6/2026 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher,… | |
| Modificada | Alta (8.8) | 1.9% | 💥 PoC | Wpdirectorykit WP Directory KIT | 5/4/2024 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Media (6.1) | 0.42% | — | Wpdirectorykit WP Directory KIT | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpDirectoryKit WP Directory Kit allows Reflected XSS.This issue affects WP Directory Kit: from n/a through 1.2.9. | |
| Modificada | Baja (2.7) | 0.51% | — | IBM Security Verify Directory | 22/3/2024 | 17/6/2026 | IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 228507. | |
| Modificada | Media (4.8) | 0.32% | — | IBM Security Verify Directory | 22/3/2024 | 17/6/2026 | IBM Security Verify Directory 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 228445. | |
| Modificada | Media (6.5) | 0.18% | — | IBM Security Verify Directory | 22/3/2024 | 17/6/2026 | IBM Security Verify Directory 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 228444. | |
| Modificada | Media (5.3) | 0.45% | — | IBM Security Verify Directory | 22/3/2024 | 17/6/2026 | IBM Security Verify Directory 10.0.0 could disclose sensitive server information that could be used in further attacks against the system. IBM X-Force ID: 228437. | |
| Modificada | Media (4.3) | 0.41% | — | Vmware Cloud Director | 7/3/2024 | 17/6/2026 | VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance. | |
| Analizada | Alta (7.8) | 0.24% | — | WUT COM Port Redirector LegacyWUT COM Port Redirector Plug & PlayWUT OPC Server | 1/3/2024 | 17/6/2026 | A local attacker can gain administrative privileges by inserting an executable file in the path of the affected product. | |
| Modificada | Media (5.3) | 0.52% | — | Wpwax Directorist | 29/2/2024 | 17/6/2026 | The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (6.8) | 0.42% | — | Microsoft Azure Active Directory | 13/2/2024 | 10/8/2026 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.31% | — | Redhat 389 Directory ServerRedhat Directory ServerFedoraproject FedoraRedhat Enterprise Linux+9 | 12/2/2024 | 17/6/2026 | A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr. | |
| Modificada | Alta (8.8) | 0.52% | — | Pingidentity Pingdirectory | 1/2/2024 | 17/6/2026 | Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server. | |
| Modificada | Media (5.4) | 0.46% | — | Miniorange Staff / Employee Business Directory FOR Active Directory | 16/1/2024 | 17/6/2026 | The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against… | |
| Modificada | Baja (2.7) | 1.3% | 💥 Exploit | Wpwax Directorist | 16/1/2024 | 17/6/2026 | The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files. | |
| Modificada | Media (6.1) | 0.32% | — | Wpdirectorykit WP Directory KIT | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Directory Kit.This issue affects WP Directory Kit: from n/a through 1.1.9. | |
| Modificada | Alta (7.2) | 0.54% | — | Ayecode Geodirectory | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified… | |
| Modificada | Media (6.1) | 0.41% | — | Ruckuswireless R750 FirmwareRuckuswireless R650 FirmwareRuckuswireless R730 FirmwareRuckuswireless T750 Firmware+33 | 7/12/2023 | 17/6/2026 | A cross-site-scripting vulnerability exists in Ruckus Access Point products (ZoneDirector, SmartZone, and AP Solo). If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is logging in the product. As for the affected products/models/versions, see the information… | |
| Modificada | Alta (8.8) | 0.28% | — | Businessdirectoryplugin Business Directory | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10. | |
| Modificada | Crítica (9.8) | 1.3% | — | Vmware Cloud Director | 14/11/2023 | 17/6/2026 | VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when… | |
| Modificada | Media (5.4) | 0.39% | — | Lava-code Lava Directory Manager | 14/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions. | |
| Modificada | Alta (7.8) | 0.20% | — | Lenovo Preload Directory | 8/11/2023 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges. | |
| Modificada | Alta (8.8) | 0.59% | — | Wpwax Directorist | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1. |