Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.49% | — | Livehelperchat Live Helper Chat | 16/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Media (6.1) | 0.88% | — | Livehelperchat Live Helper Chat | 8/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (6.5) | 0.44% | — | Livehelperchat Live Helper Chat | 7/12/2021 | 17/6/2026 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Crítica (9.6) | 1.4% | — | Django-helpdesk Project Django-helpdesk | 1/12/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.8) | 39% | — | Adobe Robohelp Server | 22/11/2021 | 17/6/2026 | Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge. | |
| Modificada | Crítica (9.8) | 1.6% | — | Algoliasearch-helper | 19/11/2021 | 17/6/2026 | The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to… | |
| Modificada | Media (5.4) | 0.80% | — | Django-helpdesk Project Django-helpdesk | 19/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.8) | 0.76% | — | Helpful Project Helpful | 17/11/2021 | 17/6/2026 | The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (6.1) | 1.0% | — | Django-helpdesk Project Django-helpdesk | 13/11/2021 | 17/6/2026 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Media (4.8) | 0.62% | — | Bookingholdings Booking.com Product Helper | 8/11/2021 | 17/6/2026 | The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.8) | 0.81% | — | Helpuviewer | 27/10/2021 | 17/6/2026 | An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator. | |
| Modificada | Media (6.1) | 0.84% | — | Faveohelpdesk Faveo | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter. | |
| Modificada | Crítica (9.8) | 5.6% | 💥 PoC | Schiocco Support Board - Chat AND Help Desk | 20/9/2021 | 17/6/2026 | The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users. | |
| Modificada | Media (5.3) | 1.2% | — | Solarwinds WEB Help Desk | 26/8/2021 | 17/6/2026 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing… | |
| Modificada | Alta (7.5) | 4.3% | 💥 PoC | Helpsystems Cobalt Strike | 9/8/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it. | |
| Modificada | Alta (7.5) | 1.0% | — | Thinkjs Think-helper | 30/6/2021 | 17/6/2026 | think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object… | |
| Modificada | Crítica (9.8) | 2.7% | — | Helpu | 29/6/2021 | 17/6/2026 | A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login. | |
| Modificada | Crítica (9.8) | 0.86% | — | Cnesty Helpcom | 29/6/2021 | 17/6/2026 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to. | |
| Modificada | Alta (8.8) | 6.2% | — | Adobe Robohelp Server | 28/6/2021 | 17/6/2026 | Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require… | |
| Modificada | Alta (8.8) | 1.1% | — | HelpuftclientHelpuftserverHelpuserverHelpuviewer | 24/6/2021 | 17/6/2026 | A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process. | |
| Modificada | Alta (8.8) | 1.2% | — | Qnap Helpdesk | 11/6/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4. | |
| Modificada | Crítica (9.8) | 0.85% | — | Cnesty Helpcom | 20/4/2021 | 17/6/2026 | A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation. | |
| Modificada | Media (6.5) | 1.6% | — | Adobe Robohelp | 19/4/2021 | 17/6/2026 | Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges. | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Woocommerce Help Scout | 5/4/2021 | 17/6/2026 | The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp. | |
| Modificada | Alta (7.8) | 0.35% | — | Bosch IP Helper | 25/3/2021 | 17/6/2026 | Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same application directory as the portable… |