Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.44% | — | Opentext Directory ServicesAI | 17/8/2026 | 1/9/2026 | A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation. This issue affects Opentext Directory Services: through 22.2. | |
| Analizada | Media (5.3) | 0.25% | — | Opentext Directory Services | 19/2/2026 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from… | |
| Aplazada | Crítica (9.5) | 0.34% | — | Opentext Directory ServicesAI | 18/2/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerability could lead to remote code execution, denial of service, or privilege escalation. This issue affects Directory Services: before 24.4.16, from 25.1 before 25.1.9, from 25.2 before 25.2.9, from 25.3… | |
| Aplazada | Media (6.3) | 0.29% | — | Opentext Directory ServicesAI | 10/7/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory Services allows Remote Code Inclusion. The vulnerability could allow access to the system via script injection.This issue affects Directory Services: 23.4. | |
| Analizada | Media (6.3) | 0.58% | — | Opentext Directory Services | 12/8/2024 | 3/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1. | |
| Aplazada | Alta (8.3) | 0.57% | — | Opentext Directory ServicesAI | 26/7/2024 | 17/6/2026 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypass in particular scenarios.This issue affects OpenText Directory Services: 24.2. | |
| Modificada | Alta (7.8) | 0.18% | — | Sonicwall Directory Services Connector | 27/10/2023 | 17/6/2026 | A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature. | |
| Modificada | Alta (8.2) | 0.89% | — | Sonicwall Directory Services Connector | 5/3/2021 | 17/6/2026 | SonicWall SSO-agent default configuration uses NetAPI to probe the associated IP's in the network, this client probing method allows a potential attacker to capture the password hash of the privileged user and potentially forces the SSO Agent to authenticate allowing an attacker to bypass firewall access controls. | |
| Modificada | Media (5) | 27% | — | Microsoft Active DirectoryMicrosoft Active Directory Application ModeMicrosoft Active Directory Lightweight Directory ServiceMicrosoft Active Directory Services | 9/4/2013 | 16/6/2026 | The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight Directory Service (AD LDS), and Active Directory Services allows remote attackers to cause a denial of service (memory consumption and service outage) via a crafted query, aka "Memory Consumption… | |
| Modificada | Alta (10) | 18% | — | Microsoft Metadirectory Services | 12/8/2002 | 16/6/2026 | Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. |