Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.32%—Dell Supportassist FOR Home PCS21/8/202417/6/2026
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.
AplazadaAlta (8.5)0.54%—Wponlinesupport Essential Plugin Timeline AND History SliderAI19/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3.
AplazadaMedia (5.4)0.34%—Benbodhi SVG SupportAI18/7/202417/6/2026
The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated…
AnalizadaMedia (6.1)0.40%—Sayedulsayem Support SVG13/7/202417/6/2026
The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
AnalizadaMedia (5.4)0.33%—Rezakhan995 Webp & SVG Support26/6/202417/6/2026
The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaAlta (7.3)0.30%—Awesomesupport Awesome Support Wordpress Helpdesk & Support12/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.
ModificadaAlta (8.8)0.30%—Getawesomesupport Awesome Support10/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaAlta (8.8)0.35%—Websupporter Filter Custom Fields & Taxonomies Light Project Websupporter Filter Custom Fields & Taxonomies Light9/6/202417/6/2026
Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05.
ModificadaMedia (5.4)0.31%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.
ModificadaCrítica (9.8)0.40%—Getawesomesupport Awesome Support9/6/202417/6/2026
Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.
ModificadaMedia (5.4)0.27%—Weavertheme Weaver Xtreme Theme Support5/6/202417/6/2026
The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaBaja (2.4)1.9%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus27/5/202417/6/2026
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.
AnalizadaCrítica (9.8)0.51%—Webidsupport Webid22/5/202417/6/2026
WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.
AnalizadaAlta (7.3)0.21%—Intel Driver & Support Assistant16/5/202417/6/2026
Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.5)0.16%—Synaptics Hardware Support APPAI14/5/202417/6/2026
Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.
AnalizadaAlta (7.8)0.25%—Intel Driver & Support Assistant3/5/202417/6/2026
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in…
AnalizadaAlta (7.8)0.33%—Intel Driver & Support Assistant3/5/202417/6/2026
Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaMedia (6.5)0.46%—Logon KB Support29/4/202417/6/2026
Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0.
AnalizadaAlta (8.8)0.74%—Webidsupport Webid19/4/202417/6/2026
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation).
AplazadaCrítica (9.9)0.76%—Support GenixAI18/4/202417/6/2026
Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
AplazadaMedia (6.5)0.32%—SupportcandyAI11/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SupportCandy allows Stored XSS.This issue affects SupportCandy: from n/a through 3.2.3.
AnalizadaAlta (8.8)0.83%💥 PoCOretnom23 Customer Support System21/3/202417/6/2026
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
AnalizadaAlta (7.3)0.32%—Root3 Support APP14/3/202417/6/2026
Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang `#!/bin/zsh` is being used. When the installer…
AnalizadaMedia (5.4)0.48%💥 PoCOretnom23 Customer Support System7/3/202417/6/2026
Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters.
AnalizadaMedia (5.4)0.45%💥 PoCOretnom23 Customer Support System6/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.