Simple-help
Simple-help Simplehelp: vulnerabilidades y CVE
Simple-help Simplehelp tiene 6 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses1
Críticas2
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48558 | Crítica (9.5) | 5.7% | ⚠ Explotación activa | 12 jun 2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during… |
| CVE-2024-57726 | Crítica (9.9) | 67% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the… |
| CVE-2024-57728 | Alta (7.2) | 65% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary… |
| CVE-2024-57727 | Alta (7.5) | 97% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48558 | Crítica (9.5) | 5.7% | ⚠ Explotación activa | 12 jun 2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during… |
| CVE-2025-36728 | Alta (8.8) | 0.17% | — | 25 jul 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11. |
| CVE-2025-36727 | Alta (8.8) | 0.42% | — | 25 jul 2025 | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.12. |
| CVE-2024-57728 | Alta (7.2) | 65% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary… |
| CVE-2024-57727 | Alta (7.5) | 97% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted… |
| CVE-2024-57726 | Crítica (9.9) | 67% | ⚠ Explotación activa | 15 ene 2025 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.