Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.56% | — | 389 Project 389 Directory ServerAI | 7/9/2026 | 8/9/2026 | A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an… | |
| Aplazada | Media (4.8) | 0.24% | — | Redirection FOR Contact Form 7AI | 6/9/2026 | 8/9/2026 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode… | |
| Aplazada | Baja (3.1) | 0.21% | — | Wpwax DirectoristAI | 4/9/2026 | 8/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts… | |
| Pendiente de análisis | Crítica (10) | 0.81% | — | Microsoft Azure Active Directory B2CAI | 3/9/2026 | 8/9/2026 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GeodirectoryAI | 3/9/2026 | 4/9/2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. | |
| Aplazada | Media (6.5) | 0.27% | — | Business DirectoryAI | 3/9/2026 | 7/9/2026 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Business DirectoryAI | 3/9/2026 | 5/9/2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |
| Analizada | Media (5.3) | 0.33% | — | Miniorange Ldap / Active Directory Integration | 2/9/2026 | 16/9/2026 | Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Drupal LDAP / Active Directory Integration allows LDAP Injection. This issue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.2.1. | |
| Aplazada | Baja (1.9) | 0.21% | — | Mapquest GET Directions APPAI | 2/9/2026 | 2/9/2026 | A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The manipulation leads to path traversal. An attack has to be approached locally. The exploit is… | |
| Pendiente de análisis | Alta (7.7) | 0.10% | — | Cloudfoundry Bosh DirectorAIVmware VcenterAI | 29/8/2026 | 3/9/2026 | Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic… | |
| Aplazada | Alta (8.8) | 0.20% | — | GeodirectoryAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Wpwax DirectoristAI | 26/8/2026 | 26/8/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Directory PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | GeodirectoryAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | MS Graph FOR Active Directory APP FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.… | |
| Aplazada | Alta (8.7) | 0.43% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly typed. Array/non-numeric values (for example limitstart[]) could trigger PHP type errors in arithmetic, and limit was not validated before use in list queries. | |
| Aplazada | Media (5.1) | 0.44% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped into an XML attribute. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause. | |
| Aplazada | Alta (7.5) | 0.42% | — | Cmsjunkie J-businessdirectoryAIJoomlaAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Open mail relay in J-BusinessDirectory < 6.2.3 - Recipient address was taken from the request (contact_id_offer / contact_id_event) instead of the server-side offer/event record, so mail could be sent to an arbitrary address. | |
| Aplazada | Media (4.6) | 0.21% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Cross-site request forgery in J-BusinessDirectory < 6.2.3 - Tokens were missing on many AJAX/state-changing tasks: contact/quote forms, cart, bookmarks, uploads, messages, AI text generation, and several administrator actions (app install, demo-data wipe, cache/statistics archive,… | |
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | |
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |
| Aplazada | Crítica (10) | 0.43% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpdirectorykit WP Directory KITAI | 19/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… |