Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1635 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.6) | 0.43% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation. | |
| Analizada | Media (6.6) | 0.37% | — | Jenkins Active Directory | 27/5/2026 | 17/6/2026 | Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default. | |
| Analizada | Media (5.3) | 0.39% | — | IBM Security Directory Integrator | 27/5/2026 | 17/6/2026 | IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Aplazada | Media (4.3) | 0.20% | — | Nikki Blight QR RedirectorAI | 25/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdirectorykit WP Directory KITAI | 21/5/2026 | 23/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0. | |
| Modificada | Alta (7.5) | 1.1% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 20/5/2026 | 21/8/2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the… | |
| Aplazada | Media (4.3) | 0.20% | — | Wp-redirectionAI | 12/5/2026 | 17/6/2026 | The WP-Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.0.3. This is due to the absence of a nonce field in the admin settings form and the lack of any nonce verification (via check_admin_referer() or wp_verify_nonce()) in the… | |
| Aplazada | Media (6.1) | 0.18% | — | TM Wordpress RedirectionAI | 12/5/2026 | 17/6/2026 | The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a… | |
| Analizada | Media (6.4) | 0.21% | 💥 PoC | Cisco IOT Field Network Director | 6/5/2026 | 29/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could… | |
| Analizada | Media (6.5) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerability is due to insufficient file access checks. An attacker could exploit this… | |
| Analizada | Alta (7.7) | 0.27% | — | Cisco IOT Field Network Director | 6/5/2026 | 30/6/2026 | A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is due to improper error handling. An attacker could exploit this vulnerability by… | |
| Aplazada | Baja (2.1) | 0.37% | — | Pixelsock Directus-mcpAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. Performing a manipulation of the argument fileUrl results in server-side request forgery. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.4) | 0.35% | — | Quantumcloud Simple Link DirectoryAI | 2/5/2026 | 17/6/2026 | The Simple Link Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `qcopd-directory` shortcode in all versions up to, and including, 8.9.2. This is due to insufficient input sanitization and output escaping on user supplied attributes such as `title_font_size`. This makes it… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Directorist Social LoginAI | 27/4/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Directorist BookingAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. | |
| Analizada | Alta (7.2) | 0.30% | — | IBM Security Verify Directory | 22/4/2026 | 7/10/2026 | IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could upload malicious files into the system that can be sent to victims for performing further attacks against the system. | |
| Modificada | Media (6.9) | 0.82% | — | Follow-redirects Project Follow-redirects | 21/4/2026 | 10/9/2026 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by… | |
| Aplazada | Alta (7.5) | 0.46% | — | Designinvento DirectorypressAI | 16/4/2026 | 17/6/2026 | The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection via the 'packages' parameter in versions up to, and including, 3.6.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Analizada | Media (6.5) | 0.27% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revision records (in directus_revisions) whenever items are created or updated. Due to the revision snapshot code not consistently calling the prepareDelta sanitization pipeline, sensitive fields… | |
| Analizada | Alta (8.8) | 0.36% | — | Monospace Directus | 9/4/2026 | 17/6/2026 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filename_disk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating… | |
| Aplazada | Media (6.5) | 0.22% | — | Manoj Kumar MK Google-directionsAIManoj Kumar MK Google-distance-calculatorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through <= 3.1.1. | |
| Aplazada | Media (5.3) | 0.26% | — | Igms Direct BookingAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through <= 1.3. | |
| Aplazada | Media (4.3) | 0.26% | — | Designinvento DirectorypressAI | 8/4/2026 | 24/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Designinvento DirectoryPress directorypress allows Retrieve Embedded Sensitive Data.This issue affects DirectoryPress: from n/a through <= 3.6.26. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpwax DirectoristAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10. |