Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
865 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU core indefinitely when processing some badly crafted Telephone Numbers. This issue affects Apache Directory LDAP API: from 2.1.0 before 2.1.9. Users are recommended to… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP server that supports this algorithm will cause the server CPU to run for hours checking the credentials. A bounded cost should be enforced to avoid a server DOS.… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead to receive data in plain text before the TLS Handshake has been completed. This issue affects Apache Directory LDAP API: from 2.1.0 before… | |
| Aplazada | Sin puntuar | — | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Deserialization of Untrusted Data vulnerability in Apache Directory LDAP API. A rogue/compromised LDAP server (or pre-TLS MITM) can answer a client's loadSchema() subschema search with a schema object that contains a serialized Java class, allowing some potential RCE. This issue affects Apache Directory LDAP API: from… | |
| Aplazada | Alta (7.3) | 0.18% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the server's decoder. This issue affects Apache Directory LDAP API: from 1.2.0 before 1.2.9. Users are recommended to upgrade to version 1.2.9, which fixes the issue. | |
| Aplazada | Sin puntuar | 0.19% | — | Apache Directory Ldap APIAI | 2/10/2026 | 2/10/2026 | Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing a large memory allocation before any data is received. This can lead to an OutOfMemoryError and denial of service. The client JVM OOMs (OutOfMemoryError… | |
| Aplazada | Alta (7.6) | 0.23% | — | Wptasty Business DirectoryAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business Directory: from n/a through 6.4.27. | |
| Aplazada | Media (5.4) | 0.21% | — | Business DirectoryAI | 30/9/2026 | 30/9/2026 | Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpdirectorykit WP Directory KITAI | 30/9/2026 | 30/9/2026 | The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (5.3) | 0.21% | — | Connections-pro Connections Business DirectoryAI | 30/9/2026 | 30/9/2026 | The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers to retrieve directory entries that are marked private or unlisted, or that are still pending moderation, including… | |
| Aplazada | Alta (7.2) | 0.30% | — | Wpdirectorykit WP Directory KITAI | 26/9/2026 | 26/9/2026 | The WP Directory Kit WordPress plugin before 1.5.8 does not sanitize and escape some of its category and location fields before outputting them in page attributes, allowing users with a WP Directory Kit WordPress plugin before 1.5.8-specific listing-management role (and without the unfiltered_html capability) to… | |
| Aplazada | Media (6.4) | 0.20% | — | GeodirectoryAI | 25/9/2026 | 25/9/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.22% | — | GeodirectoryAI | 25/9/2026 | 25/9/2026 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Media (6.5) | 0.29% | — | Wpdirectorykit WP Directory KITAI | 16/9/2026 | 17/9/2026 | The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle Internet DirectoryAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Oracle Internet DirectoryAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Oracle Internet DirectoryAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Oracle Internet DirectoryAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Aplazada | Crítica (9.9) | 0.42% | — | Oracle Internet DirectoryAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Internet Directory | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.… |