Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.7%💥 ExploitWP Accessibility Helper Project WP Accessibility Helper28/2/202217/6/2026
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat16/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaAlta (7.5)1.1%—Helpsystems Cobalt Strike15/2/202217/6/2026
CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat6/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.64%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.55%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.63%—Livehelperchat27/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.77%—Livehelperchat27/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (4.8)0.70%—Livehelperchat Live Helper Chat26/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.69%—Livehelperchat Live Helper Chat26/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (6.6)1.1%—Livehelperchat Live Helper Chat19/1/202217/6/2026
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
ModificadaMedia (4.3)0.44%—Livehelperchat18/1/202217/6/2026
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
ModificadaMedia (5.4)0.81%—Livehelperchat17/1/202217/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.3)0.43%—Livehelperchat Live Helper Chat14/1/202217/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (6.5)0.51%—Livehelperchat Live Helper Chat14/1/202217/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (5.3)0.90%—Livehelperchat Live Helper Chat4/1/202217/6/2026
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
ModificadaMedia (6.1)0.78%—Livehelperchat Live Helper Chat29/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.53%—Livehelperchat Live Helper Chat29/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.4)0.46%—Livehelperchat Live Helper Chat28/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (5.3)0.92%—Livehelperchat Live Helper Chat28/12/202117/6/2026
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
ModificadaMedia (6.1)0.30%—Solarwinds Webhelpdesk27/12/202117/6/2026
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary…
ModificadaMedia (6.1)0.95%—Livehelperchat Live Helper Chat26/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)0.90%—Solarwinds WEB Help Desk23/12/202117/6/2026
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes…
ModificadaAlta (8.8)0.54%—Livehelperchat Live Helper Chat18/12/202117/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (5.4)0.63%—Livehelperchat Live Helper Chat17/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Orbitaley — Vulnerabilidades