Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.39% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Unified Directory | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Unified Directory | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory. While the… | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.7% | — | Microsoft .net FrameworkMicrosoft Azure Active Directory | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpwax DirectoristAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud Simple Business Directory PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | |
| Analizada | Baja (3.7) | 0.36% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 8/7/2026 | 9/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though… | |
| Analizada | Media (4.4) | 0.11% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks. | |
| Analizada | Media (5.3) | 0.49% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An… | |
| Pendiente de análisis | Alta (8.8) | 0.49% | — | 389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI | 7/7/2026 | 8/7/2026 | A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds… | |
| Aplazada | Media (6.4) | 0.35% | — | CM Business DirectoryAI | 3/7/2026 | 6/7/2026 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud Simple Link DirectoryAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | |
| Aplazada | Media (6.4) | 0.23% | — | GeodirectoryAI | 2/7/2026 | 2/7/2026 | Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions. | |
| Aplazada | Crítica (9.1) | 0.76% | — | Wp-businessdirectory WP BusinessdirectoryAI | 1/7/2026 | 1/7/2026 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without… | |
| Aplazada | Media (6.5) | 0.33% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | |
| Aplazada | Media (6.1) | 0.25% | — | Business DirectoryAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | GeodirectoryAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. | |
| Analizada | Baja (3.7) | 0.33% | — | Jenkins Active Directory | 24/6/2026 | 26/6/2026 | Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Active Directory | 19/6/2026 | 24/6/2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie J-businessdirectory | 19/6/2026 | 19/8/2026 | Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the… | |
| Modificada | Media (5) | 0.35% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 18/6/2026 | 30/6/2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP… |