Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—PHD Help Desk5/9/200716/6/2026
Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.4%—Help Center Live8/8/200716/6/2026
The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1)…
ModificadaAlta (9.4)3.4%—HP Help AND Support Center12/6/200716/6/2026
Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors.
ModificadaMedia (5)1.2%—ZEN Help Desk Software ZEN Help Desk11/6/200716/6/2026
Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb.
ModificadaAlta (9.3)5.2%—BT Business Connect Webhelper Activex Control1/6/200716/6/2026
Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)4.9%💥 ExploitAdobe RobohelpAdobe Robohelp Server10/5/200716/6/2026
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2)…
ModificadaMedia (6.8)3.1%—Microgaming Download Helper Activex Control24/4/200716/6/2026
Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)31%💥 ExploitMicrosoft Html Help Workshop23/1/200716/6/2026
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.
ModificadaAlta (9.3)37%💥 ExploitMicrosoft Html Help Workshop19/1/200716/6/2026
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string.
ModificadaMedia (6.8)1.3%—Drupal Help TIP Module14/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.
ModificadaAlta (7.5)1.2%—Drupal Help TIP Module14/12/200616/6/2026
SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)2.7%💥 ExploitUltimate Helpdesk7/12/200616/6/2026
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaMedia (6.8)1.9%💥 ExploitUltimate Helpdesk7/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
ModificadaMedia (6.8)1.8%💥 ExploitCerberus Helpdesk7/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (5)1.2%—Apple BomarchivehelperApple MAC OS XApple MAC OS X Server7/12/200616/6/2026
Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the…
ModificadaMedia (6.8)2.9%💥 ExploitACE HelpdeskInverseflow Help DeskPmos Helpdesk28/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
ModificadaAlta (7.5)1.1%💥 ExploitDoug Luxem Liberum Help Desk28/11/200616/6/2026
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.3%—Doug Luxem Liberum Help Desk28/11/200616/6/2026
Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The provenance of this information is unknown; the details…
ModificadaBaja (2.6)80%💥 ExploitMicrosoft Windows NT Helper ComponentsMicrosoft Windows XP31/10/200616/6/2026
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.
ModificadaAlta (7.5)1.8%—Oneorzero Helpdesk24/10/200616/6/2026
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
ModificadaMedia (5)2.8%💥 ExploitCerberus Helpdesk20/10/200616/6/2026
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.
ModificadaAlta (7.5)1.8%—Cerberus Helpdesk5/9/200616/6/2026
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of…
ModificadaAlta (7.6)20%💥 ExploitMicrosoft Help File Viewer14/8/200616/6/2026
Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files.
ModificadaAlta (7.5)8.3%💥 ExploitTurnkey WEB Tools PHP Live Helper10/8/200616/6/2026
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.
ModificadaAlta (7.5)3.9%💥 ExploitMamboxchange A6mambohelpdesk31/7/200616/6/2026
PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
Orbitaley — Vulnerabilidades