Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.53% | — | Arcasolutions Edirectory | 5/4/2026 | 24/7/2026 | eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to authenticate as… | |
| Aplazada | Alta (8.8) | 0.30% | — | Netartmedia PHP Business DirectoryAI | 12/3/2026 | 17/6/2026 | Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted SQL payloads in the Email field to extract… | |
| Aplazada | Alta (7.2) | 0.40% | — | Name DirectoryAI | 11/3/2026 | 17/6/2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, and including, 1.32.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.1) | 0.26% | — | E-plugins Lawyer DirectoryAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Lawyer Directory lawyer-directory allows Reflected XSS.This issue affects Lawyer Directory: from n/a through <= 1.3.2. | |
| Aplazada | Alta (7.3) | 0.31% | — | E-plugins Directory PROAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6. | |
| Aplazada | Alta (7.5) | 0.36% | — | Designthemes Directory AddonAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Directory Addon: from n/a through <= 1.8. | |
| Aplazada | Media (6.5) | 0.33% | — | AdirectoryAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in aDirectory aDirectory adirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects aDirectory: from n/a through <= 3.0.3. | |
| Analizada | Media (5.3) | 0.25% | — | Opentext Directory Services | 19/2/2026 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from… | |
| Aplazada | Media (5.4) | 0.30% | — | Designinvento DirectorypressAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.26. | |
| Aplazada | Media (5.9) | 0.24% | — | Creativemindssolutions CM Business DirectoryAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.3) | 0.24% | — | Designinvento DirectorypressAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Designinvento DirectoryPress directorypress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DirectoryPress: from n/a through <= 3.6.25. | |
| Aplazada | Crítica (9.5) | 0.35% | — | Opentext Directory ServicesAI | 18/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3… | |
| Aplazada | Media (5.3) | 0.34% | — | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin for WordPress is vulnerable to authorization bypass due to a missing authorization check in all versions up to, and including, 6.4.20. This makes it possible for unauthenticated attackers to modify arbitrary listings, including changing titles, content, and email addresses, by directly… | |
| Aplazada | Alta (7.5) | 0.54% | 💥 PoC | Businessdirectoryplugin Business Directory PluginAI | 18/2/2026 | 17/6/2026 | The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the 'payment' parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Media (5.7) | 0.37% | — | Directorytree ImapengineAI | 14/2/2026 | 17/6/2026 | Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ID commands. This allows… | |
| Aplazada | Alta (7.2) | 0.27% | — | Name DirectoryAI | 10/2/2026 | 17/6/2026 | The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in all versions up to, and including, 1.32.0. This is due to the plugin's sanitization function calling `html_entity_decode()` before `wp_kses()`, and then calling `html_entity_decode()` again on… | |
| Analizada | Media (5.5) | 0.43% | — | Clive 21 Directory Management System | 8/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be… | |
| Aplazada | Media (6.4) | 0.27% | — | Employee DirectoryAI | 6/2/2026 | 17/6/2026 | The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_title' parameter in the `search_employee_directory` shortcode in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.38% | — | Clive 21 Directory Management System | 30/1/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may… | |
| Aplazada | Media (5.3) | 0.73% | 💥 Exploit | Wpdirectorykit WP Directory KITAI | 24/1/2026 | 17/6/2026 | The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles. | |
| Aplazada | Media (4.3) | 0.15% | — | Paolo GeodirectoryAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory geodirectory allows Cross Site Request Forgery.This issue affects GeoDirectory: from n/a through <= 2.8.149. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Institutions-directoryAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Institutions Directory institutions-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Institutions Directory: from n/a through <= 1.3.4. | |
| Aplazada | Alta (8.8) | 0.44% | — | E-plugins Hospital Doctor DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Hospital Doctor Directory hospital-doctor-directory allows Privilege Escalation.This issue affects Hospital Doctor Directory: from n/a through <= 1.3.9. | |
| Aplazada | Alta (8.8) | 0.44% | — | E-plugins Institutions DirectoryAI | 22/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in e-plugins Institutions Directory institutions-directory allows Privilege Escalation.This issue affects Institutions Directory: from n/a through <= 1.3.4. |