Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1634 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.56%—389 Project 389 Directory ServerAI7/9/20268/9/2026
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an…
AplazadaMedia (4.8)0.24%—Redirection FOR Contact Form 7AI6/9/20268/9/2026
The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode…
AplazadaBaja (3.1)0.21%—Wpwax DirectoristAI4/9/20268/9/2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts…
Pendiente de análisisCrítica (10)0.81%—Microsoft Azure Active Directory B2CAI3/9/20268/9/2026
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
AplazadaCrítica (9.3)0.40%—GeodirectoryAI3/9/20264/9/2026
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
AplazadaMedia (6.5)0.27%—Business DirectoryAI3/9/20267/9/2026
Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
AplazadaMedia (6.5)0.33%—Business DirectoryAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
AnalizadaMedia (5.3)0.33%—Miniorange Ldap / Active Directory Integration2/9/202616/9/2026
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1.
AplazadaBaja (1.9)0.21%—Mapquest GET Directions APPAI2/9/20262/9/2026
A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is…
Pendiente de análisisAlta (7.7)0.10%—Cloudfoundry Bosh DirectorAIVmware VcenterAI29/8/20263/9/2026
Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic…
AplazadaAlta (8.8)0.20%—GeodirectoryAI27/8/202628/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
AplazadaMedia (5.4)0.29%—Wpwax DirectoristAI26/8/202626/8/2026
The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly…
AplazadaCrítica (9.3)0.40%—Directory PROAI20/8/202620/8/2026
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
AplazadaAlta (7.1)0.25%—GeodirectoryAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Pendiente de análisisMedia (4.3)0.19%—MS Graph FOR Active Directory APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.…
AplazadaAlta (8.7)0.43%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries.
AplazadaMedia (5.1)0.44%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute.
AplazadaCrítica (9.3)0.39%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
AplazadaAlta (7.5)0.42%—Cmsjunkie J-businessdirectoryAIJoomlaAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address.
AplazadaMedia (4.6)0.21%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,…
AplazadaMedia (6.9)0.41%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
AplazadaMedia (6.9)0.41%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.
AplazadaCrítica (10)0.43%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also…
AplazadaMedia (5.3)0.34%—Wpdirectorykit WP Directory KITAI19/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own…
ModificadaCrítica (9.8)0.51%—Oracle Internet Directory18/8/202621/8/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…