Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.44% | — | Wpwax Directorist | 28/2/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having… | |
| Analizada | Alta (7.5) | 0.47% | — | Directsoftware Order Attachments FOR Woocommerce | 28/2/2025 | 17/6/2026 | The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which… | |
| Analizada | Media (5.4) | 0.23% | — | Webtamarin MK Google Directions | 28/2/2025 | 17/6/2026 | The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' shortcode in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.5) | 0.19% | — | Yibin Fengguan Network Technology Yupao DirecthireAI | 27/2/2025 | 17/6/2026 | An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.22% | — | Techmix Direct Checkout Button FOR WoocommerceAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in techmix Direct Checkout Button for WooCommerce woo-direct-checkout-button allows Stored XSS.This issue affects Direct Checkout Button for WooCommerce: from n/a through <= 1.0. | |
| Analizada | Baja (3.3) | 0.15% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 22/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores potentially sensitive information in log files that could be read by a local user. | |
| Modificada | Media (5.5) | 0.14% | — | IBM Security Verify Bridge Directory SyncIBM Security Verify Gateway FOR RadiusIBM Security Verify Gateway FOR Windows Login | 21/2/2025 | 17/6/2026 | IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 through 1.0.10, and IBM Security Verify Gateway for Radius 1.0.1 through 1.0.11 stores user credentials in configuration files which can be read by a local user. | |
| Analizada | Media (4.3) | 0.24% | — | Monospace Directus | 19/2/2025 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. In affected versions if there are two overlapping policies for the `update` action that allow access to different fields, instead of correctly checking access permissions against the item they apply for the user is allowed to update the… | |
| Aplazada | Alta (7.5) | 0.54% | — | Trash Duplicate AND 301 RedirectAI | 19/2/2025 | 17/6/2026 | The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all versions up to, and including, 1.9. This makes it possible for unauthenticated attackers to delete arbitrary posts/pages. | |
| Analizada | Media (4.3) | 0.17% | — | Designinvento Directorypress | 15/2/2025 | 17/6/2026 | The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing or incorrect nonce validation on the dpfl_listingStatusChange() function. This makes it possible for unauthenticated attackers to update listing statuses via… | |
| Aplazada | Crítica (9.8) | 0.90% | — | Alvaria Unified IP Unified DirectorAI | 14/2/2025 | 17/6/2026 | Insecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitrary code via the source and filename parameters to the ProcessUploadFromURL.jsp component. | |
| Aplazada | Crítica (9.8) | 0.64% | — | WP Directorybox ManagerAI | 13/2/2025 | 17/6/2026 | The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an… | |
| Aplazada | Media (5.4) | 0.20% | — | Intel Thread Director VisualizerAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.33% | — | Adirectory | 12/2/2025 | 17/6/2026 | The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the adqs_delete_listing() function in all versions up to, and including, 2.3. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.4) | 0.44% | — | GeodirectoryAI | 11/2/2025 | 17/6/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.75% | 💥 PoC | WP Directorybox ManagerAI | 8/2/2025 | 17/6/2026 | The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user… | |
| Analizada | Alta (8.8) | 1.1% | — | IBM Security Verify Directory | 6/2/2025 | 17/6/2026 | IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | |
| Aplazada | Crítica (9.3) | 0.89% | — | Automationdirect C-more EA9AI | 4/2/2025 | 17/6/2026 | AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device. | |
| Analizada | Media (5.3) | 0.41% | — | Wpwax Directorist | 1/2/2025 | 17/6/2026 | The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Analizada | Alta (7.5) | 0.40% | — | IBM Security Verify Directory | 31/1/2025 | 17/6/2026 | IBM Security Verify Directory 10.0 through 10.0.3 is vulnerable to a denial of service when sending an LDAP extended operation. | |
| Aplazada | Alta (7.1) | 0.26% | — | Themeglow Cleanup - Directory Listing AND ClassifiedsAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeglow Cleanup – Directory Listing & Classifieds WordPress Plugin cleanup-light allows Reflected XSS.This issue affects Cleanup – Directory Listing & Classifieds WordPress Plugin: from n/a through <= 1.0.4. | |
| Analizada | Alta (7.8) | 0.28% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.28% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.31% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target… | |
| Aplazada | Media (6.5) | 0.51% | — | Splunk Supporting Add-on FOR Active DirectoryAISplunk Sa-ldapsearchAI | 30/1/2025 | 17/6/2026 | In versions 3.1.0 and lower of the Splunk Supporting Add-on for Active Directory, also known as SA-ldapsearch, a vulnerable regular expression pattern could lead to a Regular Expression Denial of Service (ReDoS) attack. |