Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.6% | — | Fedoraproject 389 Directory ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 7/3/2018 | 17/6/2026 | An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in denial of service. | |
| Modificada | Crítica (9.8) | 1.2% | — | Microfocus EdirectoryNetiq Edirectory | 2/3/2018 | 17/6/2026 | NetIQ eDirectory before 9.0 SP4 did not enforce login restrictions when "ebaclient" was used, allowing unpermitted access to eDirectory services. | |
| Modificada | Alta (7.5) | 1.3% | — | Novell Edirectory | 2/3/2018 | 17/6/2026 | The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA. | |
| Modificada | Alta (7.5) | 1.0% | — | Novell Edirectory | 2/3/2018 | 17/6/2026 | In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations. | |
| Modificada | Alta (8.8) | 0.84% | — | Microfocus EdirectoryNetiq Edirectory | 2/3/2018 | 17/6/2026 | The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server. | |
| Modificada | Alta (7.5) | 3.9% | — | Fedoraproject 389 Directory ServerRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 1/3/2018 | 17/6/2026 | A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentially use this flaw to make ns-slapd crash via a specially crafted LDAP request, thus resulting in… | |
| Modificada | Crítica (9.8) | 2.5% | — | SAP Netweaver System Landscape Directory | 1/3/2018 | 17/6/2026 | SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity. | |
| Modificada | Alta (7.5) | 37% | 💥 Exploit | Joomlatag Jtag Members Directory | 29/1/2018 | 17/6/2026 | Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Eihitech Professional Local Directory Script | 25/1/2018 | 17/6/2026 | SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter. | |
| Modificada | Alta (8.1) | 3.8% | — | Fedoraproject 389 Directory Server | 24/1/2018 | 17/6/2026 | It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could potentially use this flaw to bypass the authentication process under very rare and specific… | |
| Modificada | Alta (8) | 1.7% | — | Oracle Internet Directory | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware (subcomponent: Oracle Directory Services Manager). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to… | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | Yourarticlesdirectory Article Directory Script | 29/10/2017 | 17/6/2026 | Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle Virtual Directory | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Virtual Directory component of Oracle Fusion Middleware (subcomponent: Virtual Directory Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Virtual… | |
| Modificada | Alta (7.5) | 2.1% | — | Fedoraproject 389 Directory ServerFedoraproject FedoraDebian Linux | 19/9/2017 | 17/6/2026 | 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call. | |
| Modificada | Alta (7.5) | 5.1% | — | Apache Directory Ldap API | 7/9/2017 | 17/6/2026 | Apache Directory LDAP API before 1.0.0-M31 allows attackers to conduct timing attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.3% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2… | |
| Modificada | Alta (8.8) | 0.75% | — | Microfocus Directory ServerMicrofocus Enterprise DeveloperMicrofocus Enterprise ServerMicrofocus Enterprise Server Monitor AND Control | 21/8/2017 | 17/6/2026 | A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter… | |
| Modificada | Crítica (9.8) | 1.4% | — | Fedoraproject 389 Directory Server | 16/8/2017 | 17/6/2026 | 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts. | |
| Modificada | Alta (8.1) | 3.6% | — | Microsoft Azure Active Directory Connect | 29/6/2017 | 17/6/2026 | Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain unauthorized access to arbitrary on-premises AD privileged user accounts aka "Azure AD Connect Elevation of Privilege Vulnerability." | |
| Modificada | Alta (7.5) | 0.65% | — | Netiq EdirectoryNetiq ImanagerNovell EdirectoryNovell Imanager | 27/4/2017 | 17/6/2026 | Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate. | |
| Modificada | Media (6.5) | 1.5% | — | Novell Edirectory | 23/3/2017 | 17/6/2026 | A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking. | |
| Modificada | Alta (7.5) | 1.2% | — | Novell Edirectory | 23/3/2017 | 17/6/2026 | NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege escalation by modifying user attributes that would otherwise be filtered by an ACL. | |
| Modificada | Alta (7.5) | 1.9% | — | Novell Edirectory | 23/3/2017 | 17/6/2026 | A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies. | |
| Modificada | Media (6.1) | 1.8% | — | Zahmit Design Connections Business Directory Plugin | 16/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable. | |
| Modificada | Media (5.5) | 0.35% | — | IBM Security Directory ServerIBM Tivoli Directory Server | 8/2/2017 | 17/6/2026 | IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash. |