Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Cnesty Helpcom | 24/2/2021 | 17/6/2026 | Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web page. | |
| Modificada | Crítica (9.8) | 3.0% | — | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3. | |
| Analizada | Crítica (9.8) | 2.0% | ⚠ Explotación activa | Qnap Helpdesk | 3/2/2021 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to… | |
| Modificada | Media (5.4) | 1.5% | — | Solarwinds WEB Help Desk | 15/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. | |
| Modificada | Media (5.4) | 1.3% | — | Solarwinds WEB Help Desk | 6/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. | |
| Modificada | Media (5.4) | 1.3% | — | Solarwinds WEB Help Desk | 4/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. | |
| Modificada | Media (5.4) | 1.7% | — | Solarwinds WEB Help Desk | 4/1/2021 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. | |
| Modificada | Media (6.5) | 1.7% | — | Solarwinds Webhelpdesk | 21/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. | |
| Modificada | Media (5.4) | 1.5% | — | Solarwinds Webhelpdesk | 18/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. | |
| Modificada | Media (5.4) | 1.7% | — | Solarwinds Webhelpdesk | 18/12/2020 | 17/6/2026 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. | |
| Modificada | Media (5.4) | 1.2% | — | Solarwinds Help Desk | 1/12/2020 | 17/6/2026 | Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. | |
| Modificada | Alta (7.5) | 1.3% | — | Evolutionscript Helpdeskz | 12/10/2020 | 17/6/2026 | An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | |
| Modificada | Media (6.1) | 1.0% | — | Livehelperchat Live Helper Chat | 2/10/2020 | 17/6/2026 | Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO. | |
| Modificada | Media (6.1) | 1.1% | — | Livehelperchat Live Helper Chat | 2/10/2020 | 17/6/2026 | Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode. | |
| Modificada | Media (6.5) | 0.30% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. | |
| Modificada | Media (6.5) | 0.76% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later. | |
| Modificada | Media (5.9) | 0.32% | — | Qnap Helpdesk | 11/9/2020 | 17/6/2026 | The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and… | |
| Modificada | Crítica (9.8) | 1.9% | — | Yola Promisehelpers | 1/9/2020 | 17/6/2026 | All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function. | |
| Modificada | Alta (7.5) | 1.0% | — | Hashicorp Vault-ssh-helper | 20/8/2020 | 17/6/2026 | HashiCorp vault-ssh-helper up to and including version 0.1.6 incorrectly accepted Vault-issued SSH OTPs for the subnet in which a host's network interface was located, rather than the specific IP address assigned to that interface. Fixed in 0.2.0. | |
| Modificada | Alta (8.2) | 1.4% | — | Oracle Help Technologies | 15/7/2020 | 17/6/2026 | Vulnerability in the Oracle Help Technologies product of Oracle Fusion Middleware (component: Web UIX). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Help Technologies. Successful… | |
| Modificada | Media (6.5) | 0.74% | — | Qnap Helpdesk | 1/7/2020 | 17/6/2026 | This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions. | |
| Modificada | Crítica (9.1) | 2.1% | — | Inetsoftware Clear ReportsInetsoftware HelpdeskInetsoftware Pdfc | 7/5/2020 | 17/6/2026 | The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal. | |
| Modificada | Alta (7.8) | 1.3% | — | Solarwinds Webhelpdesk | 27/4/2020 | 17/6/2026 | Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Watchguard AD Helper Firmware | 12/3/2020 | 17/6/2026 | The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI. | |
| Modificada | Crítica (9.8) | 4.8% | — | Helpdezk | 3/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder… |