Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)57%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
ModificadaCrítica (9.8)4.2%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.
ModificadaMedia (5.4)2.9%💥 ExploitHelpdesk PRO Project Helpdesk PRO20/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
ModificadaAlta (8.8)1.3%—Helpdezk5/9/201717/6/2026
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
ModificadaCrítica (9.8)1.2%—Helpdezk5/9/201717/6/2026
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
ModificadaMedia (5.3)9.6%💥 ExploitHelpdesk PRO Project Helpdesk PRO18/8/201717/6/2026
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.
ModificadaMedia (6.1)1.1%—Livehelperchat Live Helper Chat17/7/201717/6/2026
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (5.3)3.5%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ModificadaAlta (7.3)4.2%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
ModificadaAlta (7.5)17%—Microsoft Asp.net Model View ControllerMicrosoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorerMicrosoft.aspnetcore.mvc.cors+1412/5/201717/6/2026
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3…
ModificadaAlta (8)2.2%💥 ExploitLadybirdweb Faveo Helpdesk6/4/201717/6/2026
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
ModificadaAlta (8.8)3.5%💥 ExploitHelpdezk5/4/201717/6/2026
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
ModificadaAlta (8.8)3.1%💥 ExploitHelpdezk5/4/201717/6/2026
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
ModificadaMedia (6.1)0.66%—Helpmewatchwho Project Helpmewatchwho1/4/201717/6/2026
TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).
ModificadaMedia (6.1)3.2%—Adobe Robohelp15/12/201617/6/2026
Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
ModificadaAlta (7.5)3.5%—Adobe Robohelp12/4/201617/6/2026
Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors.
ModificadaCrítica (9.1)1.4%—Cuore Ec-cube Help Plugin19/2/201617/6/2026
SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5.8)1.5%—Services Single Sign-on Server Helper Project Services Single Sign-on Server Helper5/3/201517/6/2026
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.
ModificadaMedia (6)1.8%—Otrs Help Desk19/12/201417/6/2026
The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors.
ModificadaMedia (5.4)0.27%—Healthadvocate Health Advocate Smarthelp20/10/201417/6/2026
The Health Advocate SmartHelp (aka com.healthadvocate.ui) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Childrens Help FOR DOC20/10/201417/6/2026
The Help For Doc (aka com.childrens.physician.relations) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Makingmoneywithandroid Ingress Intel Helper9/9/201417/6/2026
The Ingress Intel Helper (aka com.bb.ingressintel) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)4.6%💥 ExploitActivehelper Livehelp Live Chat1/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in server/offline.php in the ActiveHelper LiveHelp Live Chat plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MESSAGE, (2) EMAIL, or (3) NAME parameter.
ModificadaMedia (4.3)0.79%—Eye-fi Helper3/3/201416/6/2026
Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary files via a .. (dot dot) in the filesignature in a GetPhotoStatus request.