Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.47% | 💥 PoC | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket. | |
| Analizada | Media (6.1) | 0.45% | 💥 PoC | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.45% | 💥 PoC | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Media (6.1) | 0.43% | 💥 PoC | Oretnom23 Customer Support System | 6/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list. | |
| Analizada | Crítica (9.8) | 0.82% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | |
| Analizada | Media (4.3) | 0.52% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | |
| Analizada | Alta (7.3) | 0.46% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php. | |
| Analizada | Alta (8.8) | 0.76% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | |
| Analizada | Crítica (9.8) | 1.1% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | |
| Analizada | Alta (8.8) | 0.76% | 💥 PoC | Oretnom23 Customer Support System | 5/3/2024 | 17/6/2026 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | |
| Analizada | Alta (7.5) | 0.77% | 💥 PoC | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | |
| Analizada | Media (4.9) | 0.73% | 💥 PoC | Oretnom23 Customer Support System | 1/3/2024 | 17/6/2026 | A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php. | |
| Analizada | Alta (7.5) | 0.49% | — | Open-mss Mission Support System | 15/2/2024 | 17/6/2026 | MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: `index.py`, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The `filename` variable is… | |
| Modificada | Alta (7.8) | 0.19% | — | Intel System Support Utility | 14/2/2024 | 17/6/2026 | Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 14/2/2024 | 17/6/2026 | In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code,… | |
| Modificada | Media (5.3) | 0.32% | — | Dell Supportassist FOR Home PCS | 14/2/2024 | 17/6/2026 | Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System… | |
| Modificada | Media (6.5) | 0.20% | — | Dell Supportassist FOR Home PCS | 14/2/2024 | 17/6/2026 | Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023 | |
| Modificada | Crítica (9.3) | 0.94% | — | Devfile Registry-supportRedhat OpenshiftRedhat Openshift Developer Tools AND Services | 14/2/2024 | 17/6/2026 | A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files… | |
| Modificada | Media (5.3) | 0.40% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Modificada | Media (4.3) | 0.43% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Alta (8.8) | 0.63% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Alta (7.8) | 0.64% | — | Trendmicro AIR SupportTrendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum Security+1 | 29/1/2024 | 17/6/2026 | Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, which if exploited could allow an attacker to impersonate and modify a library to execute code on the system and ultimately escalate… |