Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.35% | — | 389 Project 389 Directory ServerAI | 10/6/2026 | 30/6/2026 | A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse() and schema_oc_to_string(), but the field is still written via strcat(). An attacker with Directory Manager… | |
| Aplazada | Media (5.1) | 0.33% | — | Evoluted PHP Directory Listing ScriptAI | 9/6/2026 | 23/7/2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HTML title element and inside anchor href attributes in the breadcrumb navigation. Attackers can inject arbitrary… | |
| Modificada | Media (4.9) | 0.28% | — | Redhat 389 Directory Server | 9/6/2026 | 7/8/2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when parsing reversible-encrypted attribute values. An attacker with Directory Manager privileges can crash the LDAP server… | |
| Pendiente de análisis | Baja (3.3) | 0.26% | — | 389 Project Directory ServerAI | 9/6/2026 | 23/7/2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_string() function in auditlog.c copies a fixed-length password mask into a precisely-sized heap buffer without checking available space. If a short cleartext password is logged (requiring non-default… | |
| Modificada | Media (4.9) | 0.29% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on the iteration count extracted from stored password hashes. A privileged attacker who can modify a user's password hash can cause excessive CPU consumption during authentication, resulting in denial of… | |
| Modificada | Media (6.5) | 0.28% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when computing salt length from a crafted password hash shorter than 16 bytes, causing a buffer over-read that crashes the LDAP server during authentication. | |
| Modificada | Alta (7.5) | 0.56% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 18/8/2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure. | |
| Modificada | Media (6.3) | 0.18% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without bounds checking, causing a heap buffer over-read in string filter parsing that may influence internal filter processing behavior. | |
| Modificada | Media (6.5) | 0.16% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds read detectable under memory instrumentation. | |
| Modificada | Media (4.3) | 0.18% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 9/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated users. | |
| Aplazada | Alta (8.8) | 0.27% | — | THE Events Calendar FOR GeodirectoryAI | 9/6/2026 | 23/7/2026 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled $_POST['type'] and $_POST['postid'] values before… | |
| Modificada | Media (6.5) | 0.24% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 8/6/2026 | 23/7/2026 | A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connection teardown or… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdirectorykit WP Directory KITAI | 1/6/2026 | 22/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Paolo GeodirectoryAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157. | |
| Analizada | Alta (8.8) | 0.26% | — | Apache Directory Ldap API | 1/6/2026 | 22/7/2026 | It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP hostname. While the underlying code validates the certificate chain against a trusted authority, the absence of endpoint identification allows a valid certificate issued for an… | |
| Analizada | Media (6.6) | 0.43% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | |
| Analizada | Media (6.6) | 0.37% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | |
| Analizada | Media (5.3) | 0.39% | — | IBM Security Directory Integrator | 27/5/2026 | 17/6/2026 | IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdirectorykit WP Directory KITAI | 21/5/2026 | 23/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 20/5/2026 | 21/8/2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the… | |
| Aplazada | Media (6.4) | 0.35% | — | Quantumcloud Simple Link DirectoryAI | 2/5/2026 | 17/6/2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it… | |
| Analizada | Alta (7.2) | 0.30% | — | IBM Security Verify Directory | 22/4/2026 | 7/10/2026 | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system. | |
| Aplazada | Alta (7.5) | 0.46% | — | Designinvento DirectorypressAI | 16/4/2026 | 17/6/2026 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (4.3) | 0.26% | — | Designinvento DirectorypressAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26. |