Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1635 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.44%—Wpwax Directorist28/2/202517/6/2026
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having…
AnalizadaAlta (7.5)0.47%—Directsoftware Order Attachments FOR Woocommerce28/2/202517/6/2026
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which…
AnalizadaMedia (5.4)0.23%—Webtamarin MK Google Directions28/2/202517/6/2026
The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.5)0.19%—Yibin Fengguan Network Technology Yupao DirecthireAI27/2/202517/6/2026
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (6.5)0.22%—Techmix Direct Checkout Button FOR WoocommerceAI24/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Checkout Button for WooCommerce woo-direct-checkout-button allows Stored XSS.This issue affects Direct Checkout Button for WooCommerce: from n/a through <= 1.0.
AnalizadaBaja (3.3)0.15%—IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login22/2/202517/6/2026
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user.
ModificadaMedia (5.5)0.14%—IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login21/2/202517/6/2026
IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user.
AnalizadaMedia (4.3)0.24%—Monospace Directus19/2/202517/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of correctly checking access permissions against the item they apply for the user is allowed to update the…
AplazadaAlta (7.5)0.54%—Trash Duplicate AND 301 RedirectAI19/2/202517/6/2026
The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages.
AnalizadaMedia (4.3)0.17%—Designinvento Directorypress15/2/202517/6/2026
The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing or incorrect nonce validation on the dpfl_listingStatusChange() function. This makes it possible for unauthenticated attackers to update listing statuses via…
AplazadaCrítica (9.8)0.90%—Alvaria Unified IP Unified DirectorAI14/2/202517/6/2026
Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component.
AplazadaCrítica (9.8)0.64%—WP Directorybox ManagerAI13/2/202517/6/2026
The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an…
AplazadaMedia (5.4)0.20%—Intel Thread Director VisualizerAI12/2/202517/6/2026
Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.33%—Adirectory12/2/202517/6/2026
The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (6.4)0.44%—GeodirectoryAI11/2/202517/6/2026
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.8)0.75%💥 PoCWP Directorybox ManagerAI8/2/202517/6/2026
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user…
AnalizadaAlta (8.8)1.1%—IBM Security Verify Directory6/2/202517/6/2026
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
AplazadaCrítica (9.3)0.89%—Automationdirect C-more EA9AI4/2/202517/6/2026
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.
AnalizadaMedia (5.3)0.41%—Wpwax Directorist1/2/202517/6/2026
The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive…
AnalizadaAlta (7.5)0.40%—IBM Security Verify Directory31/1/202517/6/2026
IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation.
AplazadaAlta (7.1)0.26%—Themeglow Cleanup - Directory Listing AND ClassifiedsAI31/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4.
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.31%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target…
AplazadaMedia (6.5)0.51%—Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI30/1/202517/6/2026
In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack.
Orbitaley — Vulnerabilidades