Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)2.7%💥 ExploitGeekhelps Admp16/3/201016/6/2026
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php,…
ModificadaAlta (7.5)1.0%—Matthias Graubner MG Help15/1/201016/6/2026
SQL injection vulnerability in the Helpdesk (mg_help) extension 1.1.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)2.3%💥 ExploitViart Helpdesk4/1/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id…
ModificadaMedia (4.3)1.6%💥 ExploitCromosoft Facil Helpdesk4/1/201016/6/2026
Cross-site scripting (XSS) vulnerability in kbase/kbase.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (6.8)1.9%💥 ExploitCromosoft Facil Helpdesk4/1/201016/6/2026
PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.
ModificadaMedia (4.3)2.8%—Webworks EpublisherWebworks HelpWebworks PublisherVmware Vcenter+616/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x…
ModificadaMedia (4.3)1.9%💥 ExploitP-hd PHD Help Desk23/11/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the…
ModificadaAlta (9.3)78%💥 ExploitAdobe Robohelp Server4/9/200916/6/2026
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web…
ModificadaAlta (7.5)0.93%💥 ExploitZenhelpdesk ZEN Help Desk27/7/200916/6/2026
Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.
ModificadaAlta (7.5)2.5%💥 ExploitTeraway Livehelp12/5/200916/6/2026
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.
ModificadaMedia (4.3)1.2%—Webhelpdesk WEB Help Desk7/4/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (5)6.5%💥 ExploitOneorzero Helpdesk12/3/200916/6/2026
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.
ModificadaMedia (5)1.2%—Cerberus HelpdeskWebgroupmedia Cerberus Helpdesk6/3/200916/6/2026
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
ModificadaMedia (5)2.5%💥 ExploitFreedville Pollhelper5/3/200916/6/2026
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.
ModificadaMedia (5)2.6%💥 ExploitFreedville Bloghelper5/3/200916/6/2026
BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.
ModificadaAlta (7.5)0.97%💥 ExploitActivewebsoftwares Active WEB Helpdesk2/3/200916/6/2026
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
ModificadaMedia (4.3)2.1%—Adobe RobohelpAdobe Robohelp Server26/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 6 and 7, and RoboHelp Server 6 and 7, allows remote attackers to inject arbitrary web script or HTML via vectors involving files produced by RoboHelp.
ModificadaMedia (4.3)2.1%—Adobe RobohelpAdobe Robohelp Server26/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, which is not properly handled when displaying the Help Errors log.
ModificadaMedia (5)2.2%💥 ExploitLiberum Help Desk4/2/200916/6/2026
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.
ModificadaMedia (4.3)1.0%—Webhelpdesk WEB Help Desk27/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
ModificadaAlta (10)67%💥 ExploitMicrosoft Html Help Workshop15/1/200916/6/2026
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.
ModificadaAlta (9.3)6.7%—Componentone SizeroneSAP GUISAP TaboneServantix Tsc2 Help Desk8/1/200916/6/2026
Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and…
ModificadaMedia (5)16%—Microsoft Internet Authentication Service Helper COM Component29/9/200816/6/2026
A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause a denial of service (browser crash) via a large integer value in the first argument to the PutProperty method. NOTE: this issue was disclosed by an unreliable…
ModificadaAlta (7.5)1.8%💥 ExploitCraftysyntax Crafty Syntax Live Help27/8/200816/6/2026
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.
ModificadaMedia (5)1.2%—Craftysyntax Crafty Syntax Live Help27/8/200816/6/2026
Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.