Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.53%—Zendesk Support FOR WordpressAI9/12/202417/6/2026
Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.
ModificadaCrítica (9.8)56%—HPE Insight Remote Support27/11/202417/6/2026
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
AnalizadaAlta (7.5)84%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaAlta (7.5)47%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AnalizadaCrítica (9.8)0.72%—HPE Insight Remote Support26/11/202417/6/2026
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
AnalizadaAlta (7.5)1.5%—HPE Insight Remote Support26/11/202417/6/2026
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
AplazadaMedia (6.4)0.40%—Support SVG Upload SVG Files IN Wordpress Without HassleAI26/11/202417/6/2026
The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (5.4)0.33%—Aiphone IX SystemAIAiphone IXG SystemAIAiphone System Support SoftwareAI22/11/202417/6/2026
Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to SFTP service and obtain and/or manipulate unauthorized files.
AplazadaCrítica (9.9)0.49%—Hive SupportAI14/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a Web Shell to a Web Server.This issue affects Hive Support: from n/a through <= 1.1.1.
AnalizadaMedia (5.4)0.16%—Intel Driver & Support Assistant13/11/202417/6/2026
Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Driver & Support Assistant13/11/202417/6/2026
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (9.8)0.85%—Vanquish Woocommerce Support Ticket System9/11/202417/6/2026
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the…
AnalizadaAlta (8.1)0.93%—Vanquish Woocommerce Support Ticket System9/11/202417/6/2026
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AnalizadaCrítica (9.1)1.0%—Vanquish Woocommerce Support Ticket System9/11/202417/6/2026
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the…
AnalizadaMedia (5.4)0.30%—Benjaminzekavica Easy SVG Support8/11/202417/6/2026
The Easy SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
ModificadaCrítica (9.8)0.39%—Wpmanageninja Fluent Support1/11/202417/6/2026
Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.8.0.
AplazadaAlta (7.5)0.45%—Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+117/10/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2.
ModificadaAlta (8.5)0.42%—Wpmanageninja Fluent Support17/10/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjahan Jewel Fluent Support fluent-support allows SQL Injection.This issue affects Fluent Support: from n/a through <= 1.8.0.
AplazadaMedia (6.1)0.40%—Farsi Support Woocommerce SMSAI17/10/202417/6/2026
The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 7.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaAlta (8.8)0.21%—HP Hotkey SupportAIHP Programmable KEYAI7/10/202417/6/2026
A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for the potential vulnerability. Customers using HP Programmable Key are recommended to update HP Hotkey Support.
ModificadaMedia (6.5)0.29%—Logon KB Support1/10/202417/6/2026
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it…
ModificadaAlta (8.1)0.36%—Logon KB Support1/10/202417/6/2026
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up to, and including, 1.6.6. This makes it possible for authenticated…
AnalizadaMedia (4.8)0.31%—Mansurahamed Chatbot Support AI4/9/202417/6/2026
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…
AnalizadaMedia (6.1)1.3%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus23/8/202417/6/2026
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus: through 14800.
ModificadaMedia (5.4)1.1%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus23/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.