Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2826▼ 248 respecto a la semana anterior
Críticas / altas1321▼ 176 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1635 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying…
ModificadaMedia (5.9)0.32%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random…
ModificadaMedia (6.5)0.42%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to missing nonce verification on the get_users function and insufficient escaping on the user supplied…
ModificadaMedia (4.9)0.85%—Miniorange Active Directory Integration / Ldap Integration9/6/202317/6/2026
The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…
ModificadaMedia (5.3)0.60%—Wpdirectorykit WP Directory KIT9/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_public' function in versions up to, and including, 1.2.2. This makes it possible for unauthenticated attackers to delete or change plugin settings, import demo…
ModificadaMedia (6.5)0.61%—Wpwax Directorist9/6/202317/6/2026
The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authorization checks within the listing_task function. This makes it possible for authenticated attackers, with subscriber-level permissions and…
ModificadaAlta (8.8)0.98%—Wpwax Directorist9/6/202317/6/2026
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the password of an…
ModificadaMedia (4.3)0.77%—Quick Page/post Redirect Project Quick Page/post Redirect7/6/202317/6/2026
The Quick Page/Post Redirect Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the qppr_save_quick_redirect_ajax and qppr_delete_quick_redirect functions in versions up to, and including, 5.1.9. This makes it possible for low-privileged attackers to interact with the plugin…
ModificadaMedia (6.1)0.72%—Wpdirectorykit WP Directory KIT2/6/202317/6/2026
The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
ModificadaAlta (8.8)0.81%—Salephpscripts WEB Directory Free2/6/202317/6/2026
Web Directory Free para WordPress es vulnerable a la inyección SQL a través del parámetro "post_id" en las versiones hasta la 1.6.7 inclusive, debido a un escape insuficiente del parámetro suministrado por el usuario y a la falta de preparación suficiente de la consulta SQL existente. Esto hace posible que atacantes…
ModificadaAlta (8.8)0.27%—Name Directory Project Name Directory22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.
ModificadaMedia (4.3)0.30%—Jenkins Lightweight Directory Access Protocol16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins LDAP Plugin allows attackers to connect to an attacker-specified LDAP server using attacker-specified credentials.
ModificadaAlta (7.5)0.82%—Miniorange Active Directory Integration / Ldap Integration15/5/202317/6/2026
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.1 does not have proper authorization or nonce values for some POST requests, leading to unauthenticated data disclosure.
ModificadaMedia (4.8)0.37%—Premmerce Redirect Manager10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
ModificadaMedia (4.8)0.37%—Usbmemorydirect Simple Custom Author Profiles9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions.
ModificadaAlta (7.8)0.33%—Nokia One-network Directory Server25/4/202317/6/2026
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
ModificadaMedia (6.5)0.33%—Inisev Redirection17/4/202317/6/2026
The Redirection WordPress plugin before 1.1.5 does not have CSRF checks in the uninstall action, which could allow attackers to make logged in admins delete all the redirections through a CSRF attack.
ModificadaMedia (6.1)0.56%—External Redirect Warning Project External Redirect Warning16/4/202317/6/2026
In the External Redirect Warning Plugin 1.3 for MyBB, the redirect URL (aka external.php?url=) is vulnerable to XSS.
ModificadaMedia (4.8)0.47%—Article Directory Project Article Directory10/4/202317/6/2026
The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts.
ModificadaMedia (6.5)1.1%—Monospace Directus4/4/202317/6/2026
An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.
ModificadaMedia (6.5)0.34%—Inisev Redirection3/4/202317/6/2026
The Redirection WordPress plugin before 1.1.4 does not add nonce verification in place when adding the redirect, which could allow attackers to add redirects via a CSRF attack.
ModificadaAlta (8.8)0.91%—E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+727/3/202317/6/2026
The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before…
ModificadaCrítica (9.8)1.2%—Smplredirectionsmanager Project Smplredirectionsmanager24/3/202317/6/2026
SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.
ModificadaMedia (5.5)0.31%—Monospace Directus24/3/202317/6/2026
Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacted properly from the log outputs and can be used to impersonate users without their permission. This issue is patched in version 9.23.3.
ModificadaMedia (6.1)0.56%—Design AND Implementation OF Covid-19 Directory ON Vaccination System Project Design AND Implementation OF Covid-19 Directory ON Vaccination System11/3/202317/6/2026
A vulnerability has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file register.php. The manipulation of the argument txtfullname/txtage/txtaddress/txtphone leads to…