« Volver al listado

Simple-help

Simple-help Simplehelp: vulnerabilidades y CVE

Simple-help Simplehelp tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses1
Críticas2
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-48558Crítica (9.5)5.7%⚠ Explotación activa12 jun 2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during…
CVE-2024-57726Crítica (9.9)67%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the…
CVE-2024-57728Alta (7.2)65%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary…
CVE-2024-57727Alta (7.5)97%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-48558Crítica (9.5)5.7%⚠ Explotación activa12 jun 2026
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during…
CVE-2025-36728Alta (8.8)0.17%—25 jul 2025
Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.
CVE-2025-36727Alta (8.8)0.42%—25 jul 2025
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12.
CVE-2024-57728Alta (7.2)65%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary…
CVE-2024-57727Alta (7.5)97%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted…
CVE-2024-57726Crítica (9.9)67%⚠ Explotación activa15 ene 2025
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1210 Exploitation of Remote Services2
  3. T1005 Data from Local System1
  4. T1059 Command and Scripting Interpreter1
  5. T1078.001 Default Accounts1
  6. T1078.002 Domain Accounts1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.