Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.26%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 inserts Sensitive Information Into Sent Data to authenticated users.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows SQL Injection. Authenticated users can exploit this.
AnalizadaMedia (6.1)0.25%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication configuration data.
AnalizadaMedia (5.3)0.29%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 has Insufficiently Protected Credentials for requests to remote Excel resources.
AnalizadaMedia (5.4)0.24%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtain administrative access.
AnalizadaMedia (6.1)0.34%—Netwrix Directory Manager7/8/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data, a different vulnerability than CVE-2025-47189.
AplazadaMedia (6.1)0.26%—Netwrix Directory ManagerAI17/7/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows XSS for authentication error data of certain user flows, a different vulnerability than CVE-2025-54392.
AnalizadaCrítica (10)0.40%—Netwrix Directory Manager29/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
AnalizadaCrítica (9.1)0.43%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Data.
AnalizadaMedia (5)0.25%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) before and including v.11.0.0.0 and after v.11.1.25134.03 has Incorrect Permission Assignment for a Critical Resource.
AnalizadaMedia (5.3)0.34%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.
AnalizadaMedia (6.5)0.27%—Netwrix Directory Manager28/5/202517/6/2026
Netwrix Directory Manager (formerly Imanami GroupID) v.11.0.0.0 and before, as well as after v.11.1.25134.03 lacks Authentication for a Critical Function.
ModificadaMedia (5.4)0.39%—Lava-code Lava Directory Manager14/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
ModificadaMedia (6.1)0.33%—Lava-code Lava Directory Manager26/10/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
ModificadaAlta (7.5)1.2%—Dmxready Member Directory Manager5/2/200916/6/2026
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)3.4%—Vibechild Directory Manager5/9/200116/6/2026
edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.