Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

869 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.49%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI7/7/20268/7/2026
A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds…
AplazadaMedia (6.4)0.35%—CM Business DirectoryAI3/7/20266/7/2026
The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all versions up to, and including, 1.5.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaAlta (7.1)0.25%—Quantumcloud Simple Link DirectoryAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
AplazadaMedia (6.4)0.23%—GeodirectoryAI2/7/20262/7/2026
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
AplazadaCrítica (9.1)0.76%—Wp-businessdirectory WP BusinessdirectoryAI1/7/20261/7/2026
The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is due to insufficient path validation in the remove() method of the JBusinessDirectoryControllerUpload class. The task=upload.remove endpoint is accessible without…
AplazadaMedia (6.5)0.33%—Business DirectoryAI29/6/202629/6/2026
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
AplazadaMedia (6.5)0.22%—Business DirectoryAI29/6/202629/6/2026
Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
AplazadaMedia (6.1)0.25%—Business DirectoryAI29/6/202629/6/2026
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.22 versions.
AplazadaCrítica (9.3)0.40%—GeodirectoryAI26/6/202626/6/2026
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
AnalizadaBaja (3.7)0.33%—Jenkins Active Directory24/6/202626/6/2026
Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose…
AnalizadaCrítica (10)0.90%—Microsoft Azure Active Directory19/6/202624/6/2026
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.49%—Cmsjunkie J-businessdirectory19/6/202619/8/2026
Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the…
ModificadaMedia (5)0.35%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux18/6/202630/6/2026
A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees attribute syntax information nodes, bypassing the refcount-based deferred deletion used elsewhere in the attribute syntax subsystem. If an administrator triggers schema reload while concurrent LDAP…
AnalizadaMedia (5.4)0.23%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux17/6/202628/6/2026
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace…
AnalizadaAlta (8.6)0.37%—Oracle Unified Directory17/6/202618/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Unified Directory17/6/202619/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Unified Directory17/6/202619/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Virtual Directory17/6/202619/6/2026
Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Virtual…
AplazadaCrítica (9.9)0.48%—Wp-businessdirectoryAI15/6/202617/6/2026
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
AplazadaAlta (7.5)0.39%—Wpdirectorykit WP Directory KITAI15/6/202617/6/2026
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
AplazadaCrítica (9.3)0.40%—GeodirectoryAI15/6/202617/6/2026
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
Pendiente de análisisMedia (6.3)0.28%—Pingidentity PingdirectoryAI12/6/202628/8/2026
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.
Pendiente de análisisAlta (7.6)0.68%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI11/6/202615/7/2026
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of…
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.