Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.40% | — | Directory PROAI | 20/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | |
| Aplazada | Media (5.3) | 0.17% | — | Advanced Classifieds Directory PROAI | 10/8/2026 | 26/8/2026 | The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`. | |
| Aplazada | Alta (7.2) | 0.27% | — | Simple Link Directory PROAI | 27/7/2026 | 28/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions. | |
| Aplazada | Media (5.4) | 0.14% | — | Simple Link Directory PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Quantumcloud Simple Business Directory PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through <= 15.9.4. | |
| Aplazada | Alta (7.3) | 0.31% | — | E-plugins Directory PROAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 24/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pluginsware Advanced Classifieds & Directory Pro advanced-classifieds-and-directory-pro allows Cross Site Request Forgery.This issue affects Advanced Classifieds & Directory Pro: from n/a through <= 3.2.9. | |
| Aplazada | Media (4.3) | 0.22% | — | E-plugins Directory PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Directory Pro directory-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directory Pro: from n/a through <= 2.5.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | E-plugins Directory PROAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows Reflected XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Aplazada | Media (6.5) | 0.27% | — | E-plugins Directory PROAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Directory Pro directory-pro allows DOM-Based XSS.This issue affects Directory Pro: from n/a through <= 2.5.5. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (7.1) | 0.23% | — | Quantumcloud Simple Business Directory PROAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Reflected XSS.This issue affects Simple Business Directory Pro: from n/a through <= 15.5.1. | |
| Aplazada | Crítica (9.8) | 0.49% | — | Quantumcloud Simple Business Directory PROAI | 23/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows Privilege Escalation.This issue affects Simple Business Directory Pro: from n/a through < 15.6.9. | |
| Aplazada | Alta (8.5) | 0.51% | — | Pluginsware Advanced Classifieds AND Directory PROAI | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in PluginsWare Advanced Classifieds & Directory Pro allows Path Traversal.This issue affects Advanced Classifieds & Directory Pro: from n/a through 3.1.3. | |
| Aplazada | Media (4.3) | 0.54% | — | Advanced Classifieds Directory PROAI | 9/4/2024 | 17/6/2026 | The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the ajax_callback_delete_attachment function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with subscriber access or higher,… | |
| Modificada | Alta (8.8) | 0.27% | — | Name Directory Project Name Directory | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions. | |
| Modificada | Media (4.8) | 0.47% | — | Article Directory Project Article Directory | 10/4/2023 | 17/6/2026 | The Article Directory WordPress plugin through 1.3 does not properly sanitize the `publish_terms_text` setting before displaying it in the administration panel, which may enable administrators to conduct Stored XSS attacks in multisite contexts. | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (6.1) | 0.68% | — | Name Directory Project Name Directory | 25/7/2022 | 17/6/2026 | The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well | |
| Modificada | Media (6.1) | 0.33% | — | Name Directory Project Name Directory | 25/7/2022 | 17/6/2026 | The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them. | |
| Modificada | Alta (7.2) | 1.5% | — | Simple Schools Staff Directory Project Simple Schools Staff Directory | 20/9/2021 | 17/6/2026 | The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that are indeed images, allowing high privilege users such as admin to upload arbitrary file like PHP, leading to RCE | |
| Modificada | Alta (8.8) | 0.84% | — | Name Directory Project Name Directory | 5/2/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.0% | — | Chamber Dashboard Business Directory Project Chamber Dashboard Business Directory | 31/8/2020 | 17/6/2026 | The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS. | |
| Modificada | Media (6.5) | 1.0% | — | WT Directory Project WT Directory | 16/6/2015 | 17/6/2026 | SQL injection vulnerability in the wt_directory extension before 1.4.2 for TYPO3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | WT Directory Project WT Directory | 11/9/2014 | 17/6/2026 | SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. |