Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.77% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 podría permitir a un atacante provocar una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 228588. | |
| Modificada | Alta (8.1) | 0.50% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 especifica permisos para un recurso crítico para la seguridad de una forma que permite que dicho recurso sea leído o modificado por actores no deseados. ID de IBM X-Force: 228571. | |
| Modificada | Media (6.5) | 0.34% | — | IBM Security Directory Suite VA | 15/6/2023 | 17/6/2026 | IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 almacena las credenciales de usuario en texto sin formato que puede leer un usuario autenticado. ID de IBM X-Force: 228567. | |
| Modificada | Media (4.3) | 0.64% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete… | |
| Modificada | Crítica (9.8) | 1.7% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be… | |
| Modificada | Media (4.7) | 0.34% | — | Wpdirectorykit WP Directory KIT | 13/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious… | |
| Modificada | Media (6.5) | 0.42% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied… | |
| Modificada | Media (4.9) | 0.85% | — | Miniorange Active Directory Integration / Ldap Integration | 9/6/2023 | 17/6/2026 | The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Media (5.3) | 0.60% | — | Wpdirectorykit WP Directory KIT | 9/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo… | |
| Modificada | Media (6.5) | 0.61% | — | Wpwax Directorist | 9/6/2023 | 17/6/2026 | The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and… | |
| Modificada | Alta (8.8) | 0.98% | — | Wpwax Directorist | 9/6/2023 | 17/6/2026 | The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an… | |
| Modificada | Media (6.1) | 0.72% | — | Wpdirectorykit WP Directory KIT | 2/6/2023 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (8.8) | 0.81% | — | Salephpscripts WEB Directory Free | 2/6/2023 | 17/6/2026 | Web Directory Free para WordPress es vulnerable a la inyección SQL a través del parámetro "post_id" en las versiones hasta la 1.6.7 inclusive, debido a un escape insuficiente del parámetro suministrado por el usuario y a la falta de preparación suficiente de la consulta SQL existente. Esto hace posible que atacantes… | |
| Modificada | Alta (8.8) | 0.27% | — | Name Directory Project Name Directory | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions. | |
| Modificada | Media (4.3) | 0.30% | — | Jenkins Lightweight Directory Access Protocol | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials. | |
| Modificada | Alta (7.5) | 0.82% | — | Miniorange Active Directory Integration / Ldap Integration | 15/5/2023 | 17/6/2026 | The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure. | |
| Modificada | Alta (7.8) | 0.33% | — | Nokia One-network Directory Server | 25/4/2023 | 17/6/2026 | Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. | |
| Modificada | Media (4.8) | 0.47% | — | Article Directory Project Article Directory | 10/4/2023 | 17/6/2026 | The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts. | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (6.1) | 0.56% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to… | |
| Modificada | Media (6.1) | 0.59% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. Affected is an unknown function of the file verification.php. The manipulation of the argument txtvaccinationID leads to cross site scripting. It is possible to… | |
| Modificada | Alta (8.1) | 0.86% | — | Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System | 11/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The… | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Directory ServerFedoraproject Fedora | 27/2/2023 | 17/6/2026 | A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed… | |
| Modificada | Alta (7.2) | 0.76% | — | Wpgeodirectory Geodirectory | 27/2/2023 | 17/6/2026 | The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. |