Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Geekhelps Admp | 16/3/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php,… | |
| Modificada | Alta (7.5) | 1.0% | — | Matthias Graubner MG Help | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the Helpdesk (mg_help) extension 1.1.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Viart Helpdesk | 4/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Cromosoft Facil Helpdesk | 4/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Cromosoft Facil Helpdesk | 4/1/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | |
| Modificada | Media (4.3) | 2.8% | — | Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+6 | 16/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | P-hd PHD Help Desk | 23/11/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the… | |
| Modificada | Alta (9.3) | 78% | 💥 Exploit | Adobe Robohelp Server | 4/9/2009 | 16/6/2026 | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Zenhelpdesk ZEN Help Desk | 27/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Teraway Livehelp | 12/5/2009 | 16/6/2026 | Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie. | |
| Modificada | Media (4.3) | 1.2% | — | Webhelpdesk WEB Help Desk | 7/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Oneorzero Helpdesk | 12/3/2009 | 16/6/2026 | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter. | |
| Modificada | Media (5) | 1.2% | — | Cerberus HelpdeskWebgroupmedia Cerberus Helpdesk | 6/3/2009 | 16/6/2026 | Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Freedville Pollhelper | 5/3/2009 | 16/6/2026 | PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Freedville Bloghelper | 5/3/2009 | 16/6/2026 | BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Activewebsoftwares Active WEB Helpdesk | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Adobe RobohelpAdobe Robohelp Server | 26/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp. | |
| Modificada | Media (4.3) | 2.1% | — | Adobe RobohelpAdobe Robohelp Server | 26/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Liberum Help Desk | 4/2/2009 | 16/6/2026 | Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | |
| Modificada | Media (4.3) | 1.0% | — | Webhelpdesk WEB Help Desk | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Microsoft Html Help Workshop | 15/1/2009 | 16/6/2026 | Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564. | |
| Modificada | Alta (9.3) | 6.7% | — | Componentone SizeroneSAP GUISAP TaboneServantix Tsc2 Help Desk | 8/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and… | |
| Modificada | Media (5) | 16% | — | Microsoft Internet Authentication Service Helper COM Component | 29/9/2008 | 16/6/2026 | A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php. | |
| Modificada | Media (5) | 1.2% | — | Craftysyntax Crafty Syntax Live Help | 27/8/2008 | 16/6/2026 | Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. |