Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Simple Schools Staff Directory Project Simple Schools Staff Directory | 20/9/2021 | 17/6/2026 | The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE | |
| Modificada | Alta (7.1) | 1.4% | 💥 PoC | Microsoft Azure Active Directory ConnectMicrosoft Azure Active Directory Connect Provisioning Agent | 12/8/2021 | 10/8/2026 | Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability | |
| Modificada | Alta (7.5) | 0.79% | — | Apache Directory Studio | 26/7/2021 | 17/6/2026 | While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL authentication mechanism (DIGEST-MD5, GSSAPI) was used. While investigating DIRSTUDIO-1220 it was noticed that any configured SASL confidentiality layer was not applied. This issue affects Apache… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat 389 Directory Server | 28/5/2021 | 17/6/2026 | When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. | |
| Modificada | Media (4.3) | 0.47% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator update arbitrary payment history, such as change their status (from pending to completed to example) | |
| Modificada | Media (5.4) | 0.65% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from lack of sanitisation in the label of the Form Fields, leading to Authenticated Stored Cross-Site Scripting issues across various pages of the plugin. | |
| Modificada | Media (6.5) | 0.71% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator export files, which could then be downloaded by the attacker to get access to PII, such as email, home addresses… | |
| Modificada | Alta (7.2) | 1.6% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly check for imported files, forbidding certain extension via a blacklist approach, allowing administrator to import an archive with a .php4 inside for example, leading to RCE | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a logged in administrator import files. As the plugin also did not validate uploaded files, it could lead to RCE. | |
| Modificada | Alta (8.8) | 0.67% | — | Strategy11 Business Directory Plugin - Easy Listing Directories | 6/5/2021 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 suffered from Cross-Site Request Forgery issues, allowing an attacker to make a logged in administrator add, edit or delete form fields, which could also lead to Stored Cross-Site Scripting issues. | |
| Modificada | Media (5.3) | 1.5% | — | Redhat 389 Directory ServerRedhat Directory ServerRedhat Enterprise Linux | 26/3/2021 | 17/6/2026 | When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an unauthenticated attacker to check the existence of an entry in the LDAP database. | |
| Modificada | Alta (8.2) | 0.89% | 💥 PoC | Sonicwall Directory Services Connector | 5/3/2021 | 17/6/2026 | SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls. | |
| Modificada | Alta (8.8) | 0.84% | — | Name Directory Project Name Directory | 5/2/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Active Directory | 4/11/2020 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Active Directory Plugin 2.19 and earlier allows attackers to perform connection tests, connecting to attacker-specified or previously configured Active Directory servers using attacker-specified credentials. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Active Directory | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page. | |
| Modificada | Crítica (9.8) | 1.7% | — | Jenkins Active Directory | 4/11/2020 | 17/6/2026 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user with any password while a successful authentication of that user is still in the optional cache when using Windows/ADSI mode. | |
| Modificada | Crítica (9.8) | 1.7% | — | Jenkins Active Directory | 4/11/2020 | 17/6/2026 | Jenkins Active Directory Plugin 2.19 and earlier does not prohibit the use of an empty password in Windows/ADSI mode, which allows attackers to log in to Jenkins as any user depending on the configuration of the Active Directory server. | |
| Modificada | Crítica (9.8) | 1.3% | — | Jenkins Active Directory | 4/11/2020 | 17/6/2026 | Jenkins Active Directory Plugin 2.19 and earlier allows attackers to log in as any user if a magic constant is used as the password. | |
| Modificada | Media (5.3) | 0.93% | — | IBM Security Directory Server | 29/10/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can… | |
| Modificada | Media (5.3) | 1.1% | — | IBM Security Directory Server | 29/10/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 165949. | |
| Modificada | Media (6.1) | 1.0% | — | Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory | 31/8/2020 | 17/6/2026 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. | |
| Analizada | Crítica (10) | 99% | ⚠ Explotación activa💥 Exploit | Microsoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+11 | 17/8/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the… | |
| Modificada | Alta (8.1) | 1.0% | — | Oracle Unified Directory | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Unified Directory.… | |
| Modificada | Media (6.1) | 1.1% | — | Quantumcloud Simple Link Directory | 20/3/2020 | 17/6/2026 | An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to inject arbitrary web script or HTML, because esc_html is not called for the "echo get_the_title()" or "echo $term->name" statement. | |
| Modificada | Media (5.3) | 0.98% | — | IBM Security Directory Server | 4/2/2020 | 17/6/2026 | IBM Security Directory Server 6.4.0 stores sensitive information in URLs. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. IBM X-Force ID: 166623. |