Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)1.1%—GeodirectoryAI11/8/202613/8/2026
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers,…
AplazadaMedia (5.4)0.24%—Cube-root Directory-serveAI10/8/20263/9/2026
A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters.
AplazadaCrítica (9.1)0.74%—Cube Root Directory ServeAI10/8/202628/8/2026
A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option.
Pendiente de análisisMedia (6.5)0.43%—389 Project 389 Directory ServerAI10/8/202614/8/2026
A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization check, allowing an unauthenticated remote attacker to invoke them when nsslapd-allow-anonymous-access is enabled (the default), or any authenticated low-privilege user to…
AplazadaMedia (5.3)0.17%—Advanced Classifieds Directory PROAI10/8/202626/8/2026
The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`.
AplazadaCrítica (9.1)0.46%—Wpdirectorykit WP Directory KITAI9/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
AplazadaAlta (7.5)0.43%—GeodirectoryAI9/8/202626/8/2026
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
AplazadaMedia (6.5)0.37%—Wpdirectorykit WP Directory KITAI8/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.
AplazadaAlta (7.5)0.42%—Wpdirectorykit WP Directory KITAI8/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.
AplazadaMedia (6.5)0.37%—Wpdirectorykit WP Directory KITAI8/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.
AplazadaAlta (7.7)0.36%—Wpdirectorykit WP Directory KITAI8/8/202626/8/2026
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
AnalizadaCrítica (9.9)0.82%—Microsoft Azure Active Directory7/8/20267/8/2026
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (6.5)0.22%—Business DirectoryAI6/8/202612/8/2026
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
AplazadaMedia (6.5)0.37%—GeodirectoryAI5/8/202626/8/2026
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
AplazadaBaja (3.5)0.24%—GeodirectoryAI5/8/202629/9/2026
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example…
AnalizadaMedia (5.4)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux3/8/20269/8/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on…
ModificadaAlta (7.5)0.83%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by…
ModificadaAlta (7.5)0.53%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the…
Pendiente de análisisAlta (8.8)0.80%—Samba Active Directory Domain ControllerAI30/7/202630/7/2026
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted…
AplazadaAlta (7.5)0.51%—Salephpscripts WEB Directory FreeAI28/7/202628/7/2026
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
AplazadaAlta (7.2)0.27%—Simple Link Directory PROAI27/7/202628/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
AplazadaMedia (5.4)0.14%—Simple Link Directory PROAI23/7/202623/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.
AnalizadaAlta (8.1)0.36%—Oracle Unified Directory21/7/202630/7/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaAlta (7.2)0.49%—Oracle Unified Directory21/7/202630/7/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaAlta (8.7)0.43%—Oracle Unified Directory21/7/202628/7/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the…
Orbitaley — Vulnerabilidades