Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 1.1% | — | GeodirectoryAI | 11/8/2026 | 13/8/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.24% | — | Cube-root Directory-serveAI | 10/8/2026 | 3/9/2026 | A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | |
| Aplazada | Crítica (9.1) | 0.74% | — | Cube Root Directory ServeAI | 10/8/2026 | 28/8/2026 | A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | |
| Pendiente de análisis | Media (6.5) | 0.43% | — | 389 Project 389 Directory ServerAI | 10/8/2026 | 14/8/2026 | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to… | |
| Aplazada | Media (5.3) | 0.17% | — | Advanced Classifieds Directory PROAI | 10/8/2026 | 26/8/2026 | The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`. | |
| Aplazada | Crítica (9.1) | 0.46% | — | Wpdirectorykit WP Directory KITAI | 9/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Aplazada | Alta (7.5) | 0.43% | — | GeodirectoryAI | 9/8/2026 | 26/8/2026 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings. | |
| Aplazada | Media (6.5) | 0.37% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users. | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets. | |
| Aplazada | Media (6.5) | 0.37% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users. | |
| Aplazada | Alta (7.7) | 0.36% | — | Wpdirectorykit WP Directory KITAI | 8/8/2026 | 26/8/2026 | The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks. | |
| Analizada | Crítica (9.9) | 0.82% | — | Microsoft Azure Active Directory | 7/8/2026 | 7/8/2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.5) | 0.22% | — | Business DirectoryAI | 6/8/2026 | 12/8/2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | GeodirectoryAI | 5/8/2026 | 26/8/2026 | The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. | |
| Aplazada | Baja (3.5) | 0.24% | — | GeodirectoryAI | 5/8/2026 | 29/9/2026 | The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example… | |
| Analizada | Media (5.4) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 3/8/2026 | 9/8/2026 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on… | |
| Modificada | Alta (7.5) | 0.83% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by… | |
| Modificada | Alta (7.5) | 0.53% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 31/7/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the… | |
| Pendiente de análisis | Alta (8.8) | 0.80% | — | Samba Active Directory Domain ControllerAI | 30/7/2026 | 30/7/2026 | A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted… | |
| Aplazada | Alta (7.5) | 0.51% | — | Salephpscripts WEB Directory FreeAI | 28/7/2026 | 28/7/2026 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.27% | — | Simple Link Directory PROAI | 27/7/2026 | 28/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Link Directory PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Unified Directory | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Unified Directory | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Alta (8.7) | 0.43% | — | Oracle Unified Directory | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… |