Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

1170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.77%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 podría permitir a un atacante provocar una denegación de servicio debido al consumo incontrolado de recursos. ID de IBM X-Force: 228588.
ModificadaAlta (8.1)0.50%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 especifica permisos para un recurso crítico para la seguridad de una forma que permite que dicho recurso sea leído o modificado por actores no deseados. ID de IBM X-Force: 228571.
ModificadaMedia (6.5)0.34%—IBM Security Directory Suite VA15/6/202317/6/2026
IBM Security Directory Suite VA v8.0.1 a v8.0.1.19 almacena las credenciales de usuario en texto sin formato que puede leer un usuario autenticado. ID de IBM X-Force: 228567.
ModificadaMedia (4.3)0.64%—Wpdirectorykit WP Directory KIT13/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete…
ModificadaCrítica (9.8)1.7%—Wpdirectorykit WP Directory KIT13/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be…
ModificadaMedia (4.7)0.34%—Wpdirectorykit WP Directory KIT13/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the 'insert' function. This makes it possible for unauthenticated attackers to update the plugin's settings and inject malicious…
ModificadaMedia (6.5)0.42%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied…
ModificadaMedia (4.9)0.85%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
ModificadaMedia (5.3)0.60%—Wpdirectorykit WP Directory KIT9/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo…
ModificadaMedia (6.5)0.61%—Wpwax Directorist9/6/202317/6/2026
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and…
ModificadaAlta (8.8)0.98%—Wpwax Directorist9/6/202317/6/2026
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an…
ModificadaMedia (6.1)0.72%—Wpdirectorykit WP Directory KIT2/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaAlta (8.8)0.81%—Salephpscripts WEB Directory Free2/6/202317/6/2026
Web Directory Free para WordPress es vulnerable a la inyección SQL a través del parámetro "post_id" en las versiones hasta la 1.6.7 inclusive, debido a un escape insuficiente del parámetro suministrado por el usuario y a la falta de preparación suficiente de la consulta SQL existente. Esto hace posible que atacantes…
ModificadaAlta (8.8)0.27%—Name Directory Project Name Directory22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.
ModificadaMedia (4.3)0.30%—Jenkins Lightweight Directory Access Protocol16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.
ModificadaAlta (7.5)0.82%—Miniorange Active Directory Integration / Ldap Integration15/5/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
ModificadaAlta (7.8)0.33%—Nokia One-network Directory Server25/4/202317/6/2026
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
ModificadaMedia (4.8)0.47%—Article Directory Project Article Directory10/4/202317/6/2026
The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts.
ModificadaAlta (8.8)0.91%—E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+727/3/202317/6/2026
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before…
ModificadaMedia (6.1)0.56%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to…
ModificadaMedia (6.1)0.59%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. Affected is an unknown function of the file verification.php. The manipulation of the argument txtvaccinationID leads to cross site scripting. It is possible to…
ModificadaAlta (8.1)0.86%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument txtusername/txtpassword leads to sql injection. The…
ModificadaAlta (7.1)0.15%—Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+128/2/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,…
ModificadaMedia (5.5)0.19%—Redhat Directory ServerFedoraproject Fedora27/2/202317/6/2026
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed…
ModificadaAlta (7.2)0.76%—Wpgeodirectory Geodirectory27/2/202317/6/2026
The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.