Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

868 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.51%—Oracle Internet Directory15/9/202622/9/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…
AnalizadaCrítica (10)0.51%—Oracle Internet Directory15/9/202622/9/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…
AnalizadaCrítica (9.8)0.51%—Oracle Internet Directory15/9/202622/9/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…
AplazadaMedia (5.3)0.21%—Wpdirectorykit WP Directory KITAI15/9/202616/9/2026
The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.
AplazadaMedia (6.8)0.22%—Wpdirectorykit WP Directory KITAI15/9/202616/9/2026
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
AplazadaBaja (2.7)0.18%—Wpdirectorykit WP Directory KITAI15/9/202616/9/2026
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.
AplazadaBaja (3.5)0.26%—SEP SesamAIMicrosoft Active DirectoryAI12/9/202622/9/2026
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for…
Pendiente de análisisCrítica (9.8)0.56%—389 Directory ServerAI7/9/20268/9/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An…
Pendiente de análisisAlta (7.5)0.85%—389 Project 389 Directory ServerAI7/9/20269/9/2026
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
Pendiente de análisisAlta (7.5)0.84%—389 Project 389 Directory ServerAI7/9/20268/9/2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed…
Pendiente de análisisAlta (7.5)0.56%—389 Project 389 Directory ServerAI7/9/20268/9/2026
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an…
Pendiente de análisisCrítica (10)0.81%—Microsoft Azure Active Directory B2CAI3/9/20268/9/2026
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.3)0.40%—GeodirectoryAI3/9/20264/9/2026
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
AplazadaMedia (6.5)0.27%—Business DirectoryAI3/9/20267/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
AplazadaMedia (6.5)0.33%—Business DirectoryAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
AnalizadaMedia (5.3)0.33%—Miniorange Ldap / Active Directory Integration2/9/202616/9/2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
AplazadaAlta (8.8)0.20%—GeodirectoryAI27/8/202628/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
AplazadaCrítica (9.3)0.40%—Directory PROAI20/8/202620/8/2026
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
AplazadaAlta (7.1)0.25%—GeodirectoryAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Pendiente de análisisMedia (4.3)0.19%—MS Graph FOR Active Directory APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.…
AplazadaAlta (8.7)0.43%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries.
AplazadaMedia (5.1)0.44%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
AplazadaCrítica (9.3)0.39%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
AplazadaAlta (7.5)0.42%—Cmsjunkie J-businessdirectoryAIJoomlaAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
AplazadaMedia (4.6)0.21%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,…