Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.47%💥 PoCOretnom23 Customer Support System6/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.
AnalizadaMedia (6.1)0.45%💥 PoCOretnom23 Customer Support System6/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.
AnalizadaMedia (6.1)0.45%💥 PoCOretnom23 Customer Support System6/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.
AnalizadaMedia (6.1)0.43%💥 PoCOretnom23 Customer Support System6/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.
AnalizadaCrítica (9.8)0.82%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
AnalizadaMedia (4.3)0.52%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
AnalizadaAlta (7.3)0.46%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.
AnalizadaAlta (8.8)0.76%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.
AnalizadaCrítica (9.8)1.1%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
AnalizadaAlta (8.8)0.76%💥 PoCOretnom23 Customer Support System5/3/202417/6/2026
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
AnalizadaAlta (7.5)0.77%💥 PoCOretnom23 Customer Support System1/3/202417/6/2026
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
AnalizadaMedia (4.9)0.73%💥 PoCOretnom23 Customer Support System1/3/202417/6/2026
A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.
AnalizadaAlta (7.5)0.49%—Open-mss Mission Support System15/2/202417/6/2026
MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The `filename` variable is…
ModificadaAlta (7.8)0.19%—Intel System Support Utility14/2/202417/6/2026
Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS14/2/202417/6/2026
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code,…
ModificadaMedia (5.3)0.32%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System…
ModificadaMedia (6.5)0.20%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023
ModificadaCrítica (9.3)0.94%—Devfile Registry-supportRedhat OpenshiftRedhat Openshift Developer Tools AND Services14/2/202417/6/2026
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files…
ModificadaMedia (5.3)0.40%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and…
ModificadaMedia (4.3)0.43%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)0.63%—Getawesomesupport Awesome Support10/2/202417/6/2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
ModificadaAlta (7.8)0.64%—Trendmicro AIR SupportTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum Security+129/1/202417/6/2026
Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate…