Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.2% | — | Fedoraproject 389 Directory ServerRedhat Directory ServerRedhat Enterprise Linux | 21/8/2014 | 17/6/2026 | Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory. | |
| Modificada | Media (4.3) | 1.6% | — | Wp-business Directory Project Wp-business Directory | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin 1.0.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) search_term, (3) page_id, (4) page, or (5) page_links parameter. | |
| Modificada | Media (6.5) | 2.2% | — | Fedoraproject 389 Directory Server | 18/3/2014 | 17/6/2026 | The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind. | |
| Modificada | Alta (7.1) | 2.2% | — | IBM Global Security KITIBM Security Directory ServerIBM Tivoli Directory Server | 27/1/2014 | 17/6/2026 | IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain. | |
| Modificada | Media (4) | 2.0% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cisco Context Directory Agent (CDA) allows remote authenticated users to trigger the omission of certain user-interface data via crafted field values, aka Bug ID CSCuj45353. | |
| Modificada | Media (4.3) | 2.3% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cisco Context Directory Agent (CDA) allows remote attackers to modify the cache via a replay attack involving crafted RADIUS accounting messages, aka Bug ID CSCuj45383. | |
| Modificada | Media (4.3) | 2.2% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj45358. | |
| Modificada | Media (4.9) | 1.8% | — | Cisco Context Directory Agent | 8/1/2014 | 17/6/2026 | The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements, which allows remote authenticated users to obtain administrative access by hijacking a session, aka Bug ID CSCuj45347. | |
| Modificada | Media (4) | 2.0% | — | Redhat Enterprise LinuxFedoraproject 389 Directory ServerRedhat Directory Server | 23/11/2013 | 16/6/2026 | 389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request. | |
| Modificada | Media (5) | 37% | — | Microsoft Active Directory Lightweight Directory ServiceMicrosoft Windows Server 2008Microsoft Windows 8Microsoft Windows 7+2 | 11/9/2013 | 16/6/2026 | Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 and Active Directory Services on Windows Server 2008 SP2 and R2 SP1 and Server 2012 allow remote attackers to cause a denial of service (LDAP directory-service… | |
| Modificada | Media (5) | 2.4% | — | Fedoraproject 389 Directory Server | 10/9/2013 | 16/6/2026 | ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Myrephp Myre Business Directory | 25/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Myrephp Myre Business Directory | 25/8/2013 | 16/6/2026 | SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Media (5) | 40% | — | Microsoft Active Directory Federation Services | 14/8/2013 | 16/6/2026 | Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 allows remote attackers to obtain sensitive information about the service account, and possibly conduct account-lockout attacks, by connecting to an… | |
| Modificada | Media (4) | 1.8% | — | Fedoraproject 389 Directory ServerRedhat Directory Server | 31/7/2013 | 16/6/2026 | The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute. | |
| Modificada | Media (5) | 2.2% | — | IBM Rational Directory Server | 28/5/2013 | 16/6/2026 | IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remote attackers to obtain sensitive information by providing a crafted parameter path and then reading the debug information associated with the 500 HTTP status code. | |
| Modificada | Baja (2.6) | 2.1% | — | Fedoraproject 389 Directory Server | 13/5/2013 | 16/6/2026 | The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain… | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+7 | 29/4/2013 | 16/6/2026 | The command-line interface in Cisco Secure Access Control System (ACS), Identity Services Engine Software, Context Directory Agent, Application Networking Manager (ANM), Prime Network Control System, Prime LAN Management Solution (LMS), Prime Collaboration, Unified Provisioning Manager, Network Services Manager, Prime… | |
| Modificada | Media (5) | 27% | — | Microsoft Active DirectoryMicrosoft Active Directory Application ModeMicrosoft Active Directory Lightweight Directory ServiceMicrosoft Active Directory Services | 9/4/2013 | 16/6/2026 | The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption… | |
| Modificada | Media (5) | 2.7% | — | Fedoraproject 389 Directory Server | 13/3/2013 | 16/6/2026 | 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence. | |
| Modificada | Media (6.8) | 0.30% | — | Cisco Application Networking ManagerCisco Context Directory AgentCisco Identity Services Engine SoftwareCisco Network Services Manager+6 | 19/2/2013 | 16/6/2026 | The command-line interface in Cisco Identity Services Engine Software, Secure Access Control System (ACS), Application Networking Manager (ANM), Prime LAN Management Solution (LMS), Prime Network Control System, Quad, Context Directory Agent, Prime Collaboration, Unified Provisioning Manager, and Network Services… | |
| Modificada | Alta (10) | 59% | 💥 Exploit | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors. | |
| Modificada | Media (6.4) | 2.2% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | Unspecified vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote attackers to obtain an administrator cookie and bypass authorization checks via unknown vectors. | |
| Modificada | Media (4) | 1.9% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | dhost in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 on Windows allows remote authenticated users to cause a denial of service (daemon crash) via crafted characters in an HTTP request. | |
| Modificada | Media (4.3) | 1.8% | — | Microfocus Edirectory | 25/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |