Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Tenmiles Helpdesk Pilot | 21/12/2013 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Tenmiles Helpdesk Pilot allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI for a ticket. | |
| Modificada | Alta (10) | 3.8% | — | Adobe Robohelp | 9/10/2013 | 16/6/2026 | MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Alta (9) | 2.5% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote authenticated users to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field), leading to execution of operating-system commands. | |
| Modificada | Alta (7.5) | 1.3% | — | Wave Embassy Remote Administration ServerWave Embassy Remote Administration Server Help Desk | 15/7/2013 | 16/6/2026 | SQL injection vulnerability in the Help Desk application in Wave EMBASSY Remote Administration Server (ERAS) allows remote attackers to execute arbitrary SQL commands via the ct100$4MainController$TextBoxSearchValue parameter (aka the search field). | |
| Modificada | Media (4.3) | 1.8% | — | IBM Eclipse Help SystemIBM Spss Data Collection | 3/6/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.2% | — | Layton Technology Helpbox | 12/12/2012 | 16/6/2026 | Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network. | |
| Modificada | Media (5) | 1.2% | — | Layton Technology Helpbox | 12/12/2012 | 16/6/2026 | selectawasset.asp in Layton Helpbox 4.4.0 allows remote attackers to discover ODBC database credentials via an element=sys_asset_id request, which is not properly handled during construction of an error page. | |
| Modificada | Media (4) | 0.84% | — | Layton Technology Helpbox | 12/12/2012 | 16/6/2026 | editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data via a modified sys_request_id parameter. | |
| Modificada | Media (6.5) | 1.1% | — | Laytontechnology Helpbox | 12/12/2012 | 16/6/2026 | Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) loggedinendusername, (3) loggedinuserusergroup, (4) loggedinuser, or (5) loggedinusername cookie. | |
| Modificada | Media (4.3) | 1.1% | — | Layton Technology Helpbox | 12/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sys_solution_id, (2) sys_requesttype_id, (3) sys_problem_desc, (4) sys_solution_desc, (5) sys_problemsummary, (6) usr_Action_testing, (7) usr_Escalation, or (8)… | |
| Modificada | Alta (7.5) | 1.2% | — | Layton Technology Helpbox | 12/12/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) reqclass parameter to editrequestenduser.asp; the (2) sys_request_id parameter to editrequestuser.asp; the (3) sys_request_id parameter to enduseractions.asp; the (4) sys_request_id or… | |
| Modificada | Media (5.8) | 1.2% | — | Cups-pk-helper Project Cups-pk-helper | 20/11/2012 | 16/6/2026 | cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attackers to read or overwrite sensitive files using CUPS resources. | |
| Modificada | Media (6.3) | 0.71% | 💥 Exploit | Helpandmanual Help & Manual | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Help & Manual 5.5.1 Build 1296 allows local users to gain privileges via a Trojan horse ijl15.dll file in the current working directory, as demonstrated by a directory that contains a .hmxz, .hmxp, .hmskin, .hmx, .hm3, .hpj, .hlp, or .chm file. NOTE: some of these details are… | |
| Modificada | Media (4.3) | 2.5% | — | Adobe Robohelp | 15/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Wikiwebhelp Wiki WEB Help | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in handlers/getpage.php in Wiki Web Help 0.28 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.3% | — | Helpcenterlive Helpcenter Live | 23/9/2011 | 16/6/2026 | HelpCenter Live 2.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/HelpCenter/index.php and certain other files. | |
| Modificada | Media (4.3) | 3.0% | — | Adobe RobohelpAdobe Robohelp Server | 11/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js. | |
| Modificada | Media (4.3) | 1.7% | — | Adobe RobohelpAdobe Robohelp Server | 16/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to (1) wf_status.htm and (2) wf_topicfs.htm in RoboHTML/WildFireExt/TemplateStock/. | |
| Modificada | Media (4.3) | 1.8% | — | Adobe RobohelpAdobe Robohelp Server | 26/10/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | Adobe RobohelpAdobe Robohelp Server | 26/10/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allows remote attackers to inject arbitrary web script or HTML via vectors related to WebHelp generation with RoboHelp for Word. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | COM Huruhelpdesk | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | COM Activehelper Livehelp | 25/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER parameter to server/index.php. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Htmlcoderhelper COM Graphics | 3/5/2010 | 16/6/2026 | Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Helpcenterlive HCL | 3/5/2010 | 16/6/2026 | Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Geekhelps Admp | 16/3/2010 | 16/6/2026 | SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter. |