Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.23%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux17/6/202628/6/2026
A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Access Control Instruction) string can trigger heap-buffer-overflow writes and reads during ACI parsing. The function fails to validate that the ACI keyword has sufficient length after whitespace…
AplazadaAlta (8.5)0.36%—Wpwax Directorist BookingAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.
AnalizadaAlta (8.6)0.37%—Oracle Unified Directory17/6/202618/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Unified Directory17/6/202619/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Unified Directory17/6/202619/6/2026
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Virtual Directory17/6/202619/6/2026
Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Virtual…
AplazadaCrítica (9.9)0.48%—Wp-businessdirectoryAI15/6/202617/6/2026
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
AplazadaAlta (7.5)0.39%—Wpdirectorykit WP Directory KITAI15/6/202617/6/2026
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
AplazadaCrítica (9.3)0.40%—GeodirectoryAI15/6/202617/6/2026
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
Pendiente de análisisMedia (6.3)0.28%—Pingidentity PingdirectoryAI12/6/202628/8/2026
Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.
Pendiente de análisisAlta (7.6)0.68%—389 Project 389 Directory ServerAIFreeipaAIRedhat Identity ManagementAI11/6/202615/7/2026
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), adding sizeof(uint32_t) to a crafted SASL packet length prefix of 0xFFFFFFFC causes unsigned wraparound to zero, bypassing the nsslapd-maxsasliosize limit and leading to a heap buffer overflow of…
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.
AplazadaMedia (5.1)0.24%—Quantumcloud Simple Link DirectoryAI10/6/202623/7/2026
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks out of the string and runs script for every page visitor.
Pendiente de análisisMedia (6.5)0.35%—389 Project 389 Directory ServerAI10/6/202630/6/2026
A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager…
AplazadaMedia (5.1)0.33%—Evoluted PHP Directory Listing ScriptAI9/6/202623/7/2026
Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary…
ModificadaMedia (4.9)0.28%—Redhat 389 Directory Server9/6/20267/8/2026
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server…
Pendiente de análisisBaja (3.3)0.26%—389 Project Directory ServerAI9/6/202623/7/2026
A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default…
ModificadaMedia (4.9)0.29%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of…
ModificadaMedia (6.5)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication.
ModificadaAlta (7.5)0.56%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202618/8/2026
A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.
ModificadaMedia (6.3)0.18%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior.
ModificadaMedia (6.5)0.16%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation.
ModificadaMedia (4.3)0.18%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux9/6/202623/7/2026
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users.
AplazadaAlta (8.8)0.27%—THE Events Calendar FOR GeodirectoryAI9/6/202623/7/2026
The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before…
ModificadaMedia (6.5)0.24%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux8/6/202623/7/2026
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or…