Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

868 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.41%—Cmsjunkie J-business DirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3
AplazadaMedia (6.9)0.41%—Cmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attacker-supplied company and user IDs, including for listings that already had an owner. 6.2.3 binds the action to the authenticated user and only allows unowned listings.
AplazadaCrítica (10)0.43%—JoomlaAICmsjunkie J-businessdirectoryAI19/8/202626/8/2026
Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak extension check. CSRF token was also…
AplazadaMedia (5.3)0.34%—Wpdirectorykit WP Directory KITAI19/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own…
ModificadaCrítica (9.8)0.51%—Oracle Internet Directory18/8/202621/8/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…
ModificadaCrítica (9.9)0.43%—Oracle Internet Directory18/8/202627/8/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.…
ModificadaCrítica (10)0.51%—Oracle Internet Directory18/8/202624/8/2026
Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.…
ModificadaAlta (8.8)0.43%—Oracle Virtual Directory18/8/202628/8/2026
Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Virtual…
ModificadaAlta (7.7)0.35%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the…
ModificadaAlta (7.5)0.41%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
ModificadaMedia (6.8)0.29%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
ModificadaAlta (7.5)0.41%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
ModificadaAlta (7.5)0.41%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
ModificadaAlta (8.5)0.33%—Oracle Unified Directory18/8/202626/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the…
ModificadaAlta (8.5)0.33%—Oracle Unified Directory18/8/202621/8/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the…
AplazadaMedia (6.5)0.22%—GeodirectoryAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Pendiente de análisisAlta (7.3)0.44%—Opentext Directory ServicesAI17/8/20261/9/2026
A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2.
AplazadaAlta (7.2)0.45%—Wpdirectorykit WP Directory KITAI16/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not…
AplazadaCrítica (9.3)0.40%—Techno Dreams WEB DirectoryAI13/8/202614/8/2026
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
AplazadaAlta (7.1)0.25%—Business DirectoryAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
AplazadaCrítica (9.3)0.40%💥 PoCWpdirectorykit WP Directory KITAI13/8/202614/8/2026
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
AplazadaAlta (7.5)0.32%—Wpdirectorykit WP Directory KITAI13/8/202614/8/2026
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
AplazadaAlta (8.6)0.45%—Wpdirectorykit WP Directory KITAI12/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.
AplazadaAlta (8.1)0.39%—Wpdirectorykit WP Directory KITAI12/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
AplazadaAlta (8.1)1.1%—GeodirectoryAI11/8/202613/8/2026
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,…
Orbitaley — Vulnerabilidades