Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
868 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-business DirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 | |
| Aplazada | Media (6.9) | 0.41% | — | Cmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings. | |
| Aplazada | Crítica (10) | 0.43% | — | JoomlaAICmsjunkie J-businessdirectoryAI | 19/8/2026 | 26/8/2026 | Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also… | |
| Aplazada | Media (5.3) | 0.34% | — | Wpdirectorykit WP Directory KITAI | 19/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Internet Directory | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Modificada | Crítica (10) | 0.51% | — | Oracle Internet Directory | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Virtual Directory | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Virtual… | |
| Modificada | Alta (7.7) | 0.35% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Media (6.8) | 0.29% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Aplazada | Media (6.5) | 0.22% | — | GeodirectoryAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.44% | — | Opentext Directory ServicesAI | 17/8/2026 | 1/9/2026 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | |
| Aplazada | Alta (7.2) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 16/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Techno Dreams WEB DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Business DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Alta (8.6) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured. | |
| Aplazada | Alta (8.1) | 0.39% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 1.1% | — | GeodirectoryAI | 11/8/2026 | 13/8/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,… |