Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.6%—Fedoraproject 389 Directory ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation7/3/201817/6/2026
An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service.
ModificadaCrítica (9.8)1.2%—Microfocus EdirectoryNetiq Edirectory2/3/201817/6/2026
NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services.
ModificadaAlta (7.5)1.3%—Novell Edirectory2/3/201817/6/2026
The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
ModificadaAlta (7.5)1.0%—Novell Edirectory2/3/201817/6/2026
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
ModificadaAlta (8.8)0.84%—Microfocus EdirectoryNetiq Edirectory2/3/201817/6/2026
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
ModificadaAlta (7.5)3.9%—Fedoraproject 389 Directory ServerRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+11/3/201817/6/2026
A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in…
ModificadaCrítica (9.8)2.5%—SAP Netweaver System Landscape Directory1/3/201817/6/2026
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
ModificadaAlta (7.5)37%💥 ExploitJoomlatag Jtag Members Directory29/1/201817/6/2026
Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
ModificadaCrítica (9.8)20%💥 ExploitEihitech Professional Local Directory Script25/1/201817/6/2026
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.
ModificadaAlta (8.1)3.8%—Fedoraproject 389 Directory Server24/1/201817/6/2026
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific…
ModificadaAlta (8)1.7%—Oracle Internet Directory18/1/201817/6/2026
Vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware (subcomponent: Oracle Directory Services Manager). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to…
ModificadaCrítica (9.8)2.1%💥 ExploitYourarticlesdirectory Article Directory Script29/10/201717/6/2026
Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.
ModificadaAlta (7.5)1.4%—Oracle Virtual Directory19/10/201717/6/2026
Vulnerability in the Oracle Virtual Directory component of Oracle Fusion Middleware (subcomponent: Virtual Directory Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Virtual…
ModificadaAlta (7.5)2.1%—Fedoraproject 389 Directory ServerFedoraproject FedoraDebian Linux19/9/201717/6/2026
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
ModificadaAlta (7.5)5.1%—Apache Directory Ldap API7/9/201717/6/2026
Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors.
ModificadaMedia (6.1)1.3%—Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control21/8/201717/6/2026
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2…
ModificadaAlta (8.8)0.75%—Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control21/8/201717/6/2026
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter…
ModificadaCrítica (9.8)1.4%—Fedoraproject 389 Directory Server16/8/201717/6/2026
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
ModificadaAlta (8.1)3.6%—Microsoft Azure Active Directory Connect29/6/201717/6/2026
Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability."
ModificadaAlta (7.5)0.65%—Netiq EdirectoryNetiq ImanagerNovell EdirectoryNovell Imanager27/4/201717/6/2026
Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.
ModificadaMedia (6.5)1.5%—Novell Edirectory23/3/201717/6/2026
A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.
ModificadaAlta (7.5)1.2%—Novell Edirectory23/3/201717/6/2026
NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL.
ModificadaAlta (7.5)1.9%—Novell Edirectory23/3/201717/6/2026
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
ModificadaMedia (6.1)1.8%—Zahmit Design Connections Business Directory Plugin16/3/201717/6/2026
Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable.
ModificadaMedia (5.5)0.35%—IBM Security Directory ServerIBM Tivoli Directory Server8/2/201717/6/2026
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
Orbitaley — Vulnerabilidades