Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1634 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Internet Directory | 18/8/2026 | 27/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Modificada | Crítica (10) | 0.51% | — | Oracle Internet Directory | 18/8/2026 | 24/8/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Modificada | Alta (8.8) | 0.43% | — | Oracle Virtual Directory | 18/8/2026 | 28/8/2026 | Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Virtual… | |
| Modificada | Alta (7.7) | 0.35% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Media (6.8) | 0.29% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (7.5) | 0.41% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Aplazada | Media (6.5) | 0.22% | — | GeodirectoryAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.44% | — | Opentext Directory ServicesAI | 17/8/2026 | 1/9/2026 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | |
| Aplazada | Alta (7.2) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 16/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not… | |
| Aplazada | Alta (7.7) | 0.33% | — | Directoriespro Directories PROAI | 13/8/2026 | 14/8/2026 | Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Techno Dreams WEB DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Business DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Media (4.7) | 0.42% | — | Probo SaferedirectAIProbodAI | 13/8/2026 | 18/9/2026 | Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo's `saferedirect` package validates redirect URLs used across authentication flows (OIDC, SAML, session transfer, OAuth connectors, and trust-center magic links). Prior to version 0.19.3.1, the… | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Aplazada | Alta (8.6) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured. | |
| Aplazada | Alta (8.1) | 0.39% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 1.1% | — | GeodirectoryAI | 11/8/2026 | 13/8/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. |