Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.32% | — | Dell Supportassist FOR Home PCS | 21/8/2024 | 17/6/2026 | Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges. | |
| Aplazada | Alta (8.5) | 0.54% | — | Wponlinesupport Essential Plugin Timeline AND History SliderAI | 19/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and History slider allows PHP Local File Inclusion.This issue affects Timeline and History slider: from n/a through 2.3. | |
| Aplazada | Media (5.4) | 0.34% | — | Benbodhi SVG SupportAI | 18/7/2024 | 17/6/2026 | The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature in all versions up to, and including, 2.5.7 due to insufficient input sanitization and output escaping, even when the 'Sanitize SVG while uploading' feature is enabled. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.40% | — | Sayedulsayem Support SVG | 13/7/2024 | 17/6/2026 | The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks. | |
| Analizada | Media (5.4) | 0.33% | — | Rezakhan995 Webp & SVG Support | 26/6/2024 | 17/6/2026 | The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Alta (7.3) | 0.30% | — | Awesomesupport Awesome Support Wordpress Helpdesk & Support | 12/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.30% | — | Getawesomesupport Awesome Support | 10/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Alta (8.8) | 0.35% | — | Websupporter Filter Custom Fields & Taxonomies Light Project Websupporter Filter Custom Fields & Taxonomies Light | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Websupporter Filter Custom Fields & Taxonomies Light.This issue affects Filter Custom Fields & Taxonomies Light: from n/a through 1.05. | |
| Modificada | Media (5.4) | 0.31% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6. | |
| Modificada | Crítica (9.8) | 0.40% | — | Getawesomesupport Awesome Support | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7. | |
| Modificada | Media (5.4) | 0.27% | — | Weavertheme Weaver Xtreme Theme Support | 5/6/2024 | 17/6/2026 | The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div shortcode in all versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.4) | 1.9% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 27/5/2024 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users. | |
| Analizada | Crítica (9.8) | 0.51% | — | Webidsupport Webid | 22/5/2024 | 17/6/2026 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. | |
| Analizada | Alta (7.3) | 0.21% | — | Intel Driver & Support Assistant | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.5) | 0.16% | — | Synaptics Hardware Support APPAI | 14/5/2024 | 17/6/2026 | Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App. | |
| Analizada | Alta (7.8) | 0.25% | — | Intel Driver & Support Assistant | 3/5/2024 | 17/6/2026 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Analizada | Alta (7.8) | 0.33% | — | Intel Driver & Support Assistant | 3/5/2024 | 17/6/2026 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Intel Driver & Support Assistant. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Media (6.5) | 0.46% | — | Logon KB Support | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0. | |
| Analizada | Alta (8.8) | 0.74% | — | Webidsupport Webid | 19/4/2024 | 17/6/2026 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing attackers to buy now an auction that is suspended (horizontal privilege escalation). | |
| Aplazada | Crítica (9.9) | 0.76% | — | Support GenixAI | 18/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3. | |
| Aplazada | Media (6.5) | 0.32% | — | SupportcandyAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SupportCandy allows Stored XSS.This issue affects SupportCandy: from n/a through 3.2.3. | |
| Analizada | Alta (8.8) | 0.83% | 💥 PoC | Oretnom23 Customer Support System | 21/3/2024 | 17/6/2026 | Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators. | |
| Analizada | Alta (7.3) | 0.32% | — | Root3 Support APP | 14/3/2024 | 17/6/2026 | Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the installer execute arbitrary code as root. The cause of the vulnerability is the fact that the shebang `#!/bin/zsh` is being used. When the installer… | |
| Analizada | Media (5.4) | 0.48% | 💥 PoC | Oretnom23 Customer Support System | 7/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters. | |
| Analizada | Media (5.4) | 0.45% | 💥 PoC | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer. |