Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | WP Accessibility Helper Project WP Accessibility Helper | 28/2/2022 | 17/6/2026 | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.61% | — | Livehelperchat Live Helper Chat | 16/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Alta (7.5) | 1.1% | — | Helpsystems Cobalt Strike | 15/2/2022 | 17/6/2026 | CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL. | |
| Modificada | Media (5.4) | 0.61% | — | Livehelperchat Live Helper Chat | 6/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.64% | — | Livehelperchat Live Helper Chat | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.55% | — | Livehelperchat Live Helper Chat | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.63% | — | Livehelperchat | 27/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.77% | — | Livehelperchat | 27/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (4.8) | 0.70% | — | Livehelperchat Live Helper Chat | 26/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.69% | — | Livehelperchat Live Helper Chat | 26/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (6.6) | 1.1% | — | Livehelperchat Live Helper Chat | 19/1/2022 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v. | |
| Modificada | Media (4.3) | 0.44% | — | Livehelperchat | 18/1/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0. | |
| Modificada | Media (5.4) | 0.81% | — | Livehelperchat | 17/1/2022 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.3) | 0.43% | — | Livehelperchat Live Helper Chat | 14/1/2022 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Media (6.5) | 0.51% | — | Livehelperchat Live Helper Chat | 14/1/2022 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Media (5.3) | 0.90% | — | Livehelperchat Live Helper Chat | 4/1/2022 | 17/6/2026 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | |
| Modificada | Media (6.1) | 0.78% | — | Livehelperchat Live Helper Chat | 29/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.53% | — | Livehelperchat Live Helper Chat | 29/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.4) | 0.46% | — | Livehelperchat Live Helper Chat | 28/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (5.3) | 0.92% | — | Livehelperchat Live Helper Chat | 28/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | |
| Modificada | Media (6.1) | 0.30% | — | Solarwinds Webhelpdesk | 27/12/2021 | 17/6/2026 | Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password hashes of the users or insert arbitrary… | |
| Modificada | Media (6.1) | 0.95% | — | Livehelperchat Live Helper Chat | 26/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 0.90% | — | Solarwinds WEB Help Desk | 23/12/2021 | 17/6/2026 | The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method requests that the origin server removes… | |
| Modificada | Alta (8.8) | 0.54% | — | Livehelperchat Live Helper Chat | 18/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Media (5.4) | 0.63% | — | Livehelperchat Live Helper Chat | 17/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |