Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Turnkeywebtools PHP Live Helper | 21/8/2008 | 16/6/2026 | Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via the test parameter, and probably arbitrary parameters, to chat.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Turnkeywebtools PHP Live Helper | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Turnkeywebtools PHP Live Helper | 21/8/2008 | 16/6/2026 | Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Crafty Syntax Live Help | 7/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attackers to inject arbitrary web script or HTML via the department parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Linuxwebshop PHP Help Agent | 30/7/2008 | 16/6/2026 | Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname… | |
| Modificada | Media (6.1) | 17% | — | Adobe Robohelp Server | 9/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Help Errors log. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Eztechhelp Company Ezcms | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Eztechhelp Ezcms | 30/6/2008 | 16/6/2026 | admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | |
| Modificada | Alta (7.2) | 0.30% | — | Fedora 8 ConsolehelperRedhat Fedora 8 | 2/6/2008 | 16/6/2026 | The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration. | |
| Modificada | Media (4.3) | 1.0% | — | Crafty Syntax Live Help | 6/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE: the lostsheep.php vector is covered by CVE-2008-0848. | |
| Modificada | Media (4.3) | 1.3% | — | Crafty Syntax Live Help | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are probably incorrect. | |
| Modificada | Media (6.1) | 1.3% | — | Adobe Robohelp | 15/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-1280. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Astrosoft Helpdesk | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for… | |
| Modificada | Media (6.5) | 0.93% | — | Layton Technology Helpbox | 9/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Layton HelpBox 3.7.1 allow (1) remote attackers to execute arbitrary SQL commands via the sys_request_id parameter to editrequestenduser.asp; and allow remote authenticated users to execute arbitrary SQL commands via (2) the oldpassword parameter to writepwdenduser.asp, and… | |
| Modificada | Media (5) | 1.2% | — | Layton Technology Helpbox | 9/1/2008 | 16/6/2026 | Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Baja (3.5) | 1.1% | — | Layton Technology Helpbox | 9/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Layton HelpBox 3.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Forename, (2) Surname, (3) Telephone, and (4) Fax fields to writeenduserenduser.asp; the (5) Filter field to statsrequestypereport.asp; and the (6)… | |
| Modificada | Media (6.5) | 1.1% | — | Layton Technology Helpbox | 9/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not properly checking file extensions. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Pmos Helpdesk | 28/12/2007 | 16/6/2026 | form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter. | |
| Modificada | Media (6.8) | 7.1% | 💥 Exploit | Viart CMSViart HelpdeskViart Shop EvaluationViart Shop Free | 13/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 1.1% | — | Phphelpdesk | 10/11/2007 | 16/6/2026 | SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures." | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Phphelpdesk | 10/11/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Oneorzero Helpdesk | 30/10/2007 | 16/6/2026 | Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description… | |
| Modificada | Alta (9.3) | 8.8% | 💥 Exploit | Btglobalservices BT Consumer Webhelper | 25/10/2007 | 16/6/2026 | Multiple buffer overflows in the British Telecommunications Consumer webhelper ActiveX control before 2.0.0.8 in btwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Grouplink Ehelpdesk | 3/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | David Watters Helplink | 26/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. |