Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
868 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Aplazada | Media (5.3) | 0.21% | — | Wpdirectorykit WP Directory KITAI | 15/9/2026 | 16/9/2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users. | |
| Aplazada | Media (6.8) | 0.22% | — | Wpdirectorykit WP Directory KITAI | 15/9/2026 | 16/9/2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered. | |
| Aplazada | Baja (2.7) | 0.18% | — | Wpdirectorykit WP Directory KITAI | 15/9/2026 | 16/9/2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users. | |
| Aplazada | Baja (3.5) | 0.26% | — | SEP SesamAIMicrosoft Active DirectoryAI | 12/9/2026 | 22/9/2026 | SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for… | |
| Pendiente de análisis | Crítica (9.8) | 0.56% | — | 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An… | |
| Pendiente de análisis | Alta (7.5) | 0.85% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 9/9/2026 | A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.84% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed… | |
| Pendiente de análisis | Alta (7.5) | 0.56% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | Microsoft Azure Active Directory B2CAI | 3/9/2026 | 8/9/2026 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GeodirectoryAI | 3/9/2026 | 4/9/2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Business DirectoryAI | 3/9/2026 | 7/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Business DirectoryAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Aplazada | Alta (8.8) | 0.20% | — | GeodirectoryAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Directory PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | GeodirectoryAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | MS Graph FOR Active Directory APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.… | |
| Aplazada | Alta (8.7) | 0.43% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries. | |
| Aplazada | Media (5.1) | 0.44% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause. | |
| Aplazada | Alta (7.5) | 0.42% | — | Cmsjunkie J-businessdirectoryAIJoomlaAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address. | |
| Aplazada | Media (4.6) | 0.21% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,… |