Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.49%—Livehelperchat Live Helper Chat16/12/202117/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaMedia (6.1)0.88%—Livehelperchat Live Helper Chat8/12/202117/6/2026
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (6.5)0.44%—Livehelperchat Live Helper Chat7/12/202117/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaCrítica (9.6)1.4%—Django-helpdesk Project Django-helpdesk1/12/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.8)39%—Adobe Robohelp Server22/11/202117/6/2026
Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in Bridge.
ModificadaCrítica (9.8)1.6%—Algoliasearch-helper19/11/202117/6/2026
The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in src/SearchParameters/index.jsSearchParameters._parseNumbers without any protection against prototype properties. Note that this vulnerability is only exploitable if the implementation allows users to…
ModificadaMedia (5.4)0.80%—Django-helpdesk Project Django-helpdesk19/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.8)0.76%—Helpful Project Helpful17/11/202117/6/2026
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.1)1.0%—Django-helpdesk Project Django-helpdesk13/11/202117/6/2026
django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaMedia (4.8)0.62%—Bookingholdings Booking.com Product Helper8/11/202117/6/2026
The Booking.com Product Helper WordPress plugin before 1.0.2 does not sanitize and escape Product Code when creating Product Shortcode, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.8)0.81%—Helpuviewer27/10/202117/6/2026
An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with privilege of administrator.
ModificadaMedia (6.1)0.84%—Faveohelpdesk Faveo1/10/202117/6/2026
Cross-site scripting (XSS) vulnerability in dompdf/dompdf/www/demo.php infaveo-helpdesk v1.11.0 and below allow remote attackers to inject arbitrary web script or HTML via the $_SERVER["PHP_SELF"] parameter.
ModificadaCrítica (9.8)5.6%💥 PoCSchiocco Support Board - Chat AND Help Desk20/9/202117/6/2026
The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users.
ModificadaMedia (5.3)1.2%—Solarwinds WEB Help Desk26/8/202117/6/2026
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing…
ModificadaAlta (7.5)4.3%💥 PoCHelpsystems Cobalt Strike9/8/202117/6/2026
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
ModificadaAlta (7.5)1.0%—Thinkjs Think-helper30/6/202117/6/2026
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object…
ModificadaCrítica (9.8)2.7%—Helpu29/6/202117/6/2026
A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.
ModificadaCrítica (9.8)0.86%—Cnesty Helpcom29/6/202117/6/2026
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient validation of the parameter. This issue affects: Cnesty Helpcom 10.0 versions prior to.
ModificadaAlta (8.8)6.2%—Adobe Robohelp Server28/6/202117/6/2026
Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require…
ModificadaAlta (8.8)1.1%—HelpuftclientHelpuftserverHelpuserverHelpuviewer24/6/202117/6/2026
A vulnerability in agent program of HelpU remote control solution could allow an authenticated remote attacker to execute arbitrary commands This vulnerability is due to insufficient input santization when communicating customer process.
ModificadaAlta (8.8)1.2%—Qnap Helpdesk11/6/202117/6/2026
An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.
ModificadaCrítica (9.8)0.85%—Cnesty Helpcom20/4/202117/6/2026
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation.
ModificadaMedia (6.5)1.6%—Adobe Robohelp19/4/202117/6/2026
Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with admin permissions to write to the file system could leverage this vulnerability to escalate privileges.
ModificadaCrítica (9.8)7.9%💥 ExploitWoocommerce Help Scout5/4/202117/6/2026
The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allows unauthenticated users to upload any files to the site which by default will end up in wp-content/uploads/hstmp.
ModificadaAlta (7.8)0.35%—Bosch IP Helper25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same application directory as the portable…
Orbitaley — Vulnerabilidades