Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.40%—Techno Dreams WEB DirectoryAI13/8/202614/8/2026
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
AplazadaAlta (7.5)0.51%—Salephpscripts WEB Directory FreeAI28/7/202628/7/2026
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…
AplazadaMedia (6.5)0.16%—Salephpscripts WEB Directory FreeAI30/12/20251/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows DOM-Based XSS.This issue affects Web Directory Free: from n/a through <= 1.7.12.
AplazadaAlta (7.1)0.23%—Salephpscripts WEB Directory FreeAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8.
AplazadaAlta (7.1)0.15%—Salephpscripts WEB Directory FreeAI3/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shamalli Web Directory Free web-directory-free allows Stored XSS.This issue affects Web Directory Free: from n/a through <= 1.7.6.
AplazadaCrítica (9.3)0.36%—Salephpscripts WEB Directory FreeAI25/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shamalli Web Directory Free web-directory-free allows Blind SQL Injection.This issue affects Web Directory Free: from n/a through <= 1.7.6.
AplazadaAlta (7.1)0.32%—Salephpscripts WEB Directory FreeAI5/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.3.
AnalizadaCrítica (9.1)5.6%—Salephpscripts WEB Directory Free30/8/202417/6/2026
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
AnalizadaMedia (6.8)0.50%—Salephpscripts WEB Directory Free30/7/202417/6/2026
The Web Directory Free WordPress plugin before 1.7.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)67%—Salephpscripts WEB Directory Free13/6/202417/6/2026
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.
ModificadaAlta (8.8)0.81%—Salephpscripts WEB Directory Free2/6/202317/6/2026
The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with…
ModificadaMedia (6.8)0.95%—Source Workshop WEB Directory Script15/9/200816/6/2026
SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.
ModificadaAlta (7.5)1.2%—Nullscripts WEB Directory Script26/8/200816/6/2026
SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.
ModificadaAlta (7.8)1.7%—Techno Dreams WEB Directory1/6/200716/6/2026
Techno Dreams Web Directory / Search Engine 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database.mdb.
ModificadaMedia (6.4)1.5%—WEB Directory PRO15/11/200616/6/2026
Web Directory Pro allows remote attackers to (1) backup the database and obtain the backup via a direct request to admin/backup_db.php or (2) modify configuration via a direct request to admin/options.php.
ModificadaAlta (7.5)1.6%—Techno Dreams WEB Directory30/10/200516/6/2026
SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.