Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.5) | 0.33% | — | Oracle Unified Directory | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Aplazada | Media (6.5) | 0.22% | — | GeodirectoryAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions. | |
| Pendiente de análisis | Alta (7.3) | 0.44% | — | Opentext Directory ServicesAI | 17/8/2026 | 1/9/2026 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | |
| Aplazada | Alta (7.2) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 16/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not… | |
| Aplazada | Alta (7.7) | 0.33% | — | Directoriespro Directories PROAI | 13/8/2026 | 14/8/2026 | Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Techno Dreams WEB DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Business DirectoryAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | 💥 PoC | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Wpdirectorykit WP Directory KITAI | 13/8/2026 | 14/8/2026 | Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. | |
| Aplazada | Alta (8.6) | 0.45% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured. | |
| Aplazada | Alta (8.1) | 0.39% | — | Wpdirectorykit WP Directory KITAI | 12/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 1.1% | — | GeodirectoryAI | 11/8/2026 | 13/8/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Pendiente de análisis | Media (6.5) | 0.43% | — | 389 Project 389 Directory ServerAI | 10/8/2026 | 14/8/2026 | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to… | |
| Aplazada | Media (5.3) | 0.17% | — | Advanced Classifieds Directory PROAI | 10/8/2026 | 26/8/2026 | The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Wpdirectorykit WP Directory KITAI | 9/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Aplazada | Alta (7.5) | 0.43% | — | GeodirectoryAI | 9/8/2026 | 26/8/2026 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings. | |
| Aplazada | Media (6.5) | 0.37% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets. | |
| Aplazada | Media (6.5) | 0.37% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users. | |
| Aplazada | Alta (7.7) | 0.36% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |
| Analizada | Crítica (9.9) | 0.82% | — | Microsoft Azure Active Directory | 7/8/2026 | 7/8/2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.5) | 0.22% | — | Business DirectoryAI | 6/8/2026 | 12/8/2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | GeodirectoryAI | 5/8/2026 | 26/8/2026 | The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. |