Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | PHD Help Desk | 5/9/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHD Help Desk before 1.31 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Help Center Live | 8/8/2007 | 16/6/2026 | The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1)… | |
| Modificada | Alta (9.4) | 3.4% | — | HP Help AND Support Center | 12/6/2007 | 16/6/2026 | Buffer overflow in Help and Support Center before 4.4 C on HP Windows systems allows remote attackers to read or write arbitrary files via unknown vectors. | |
| Modificada | Media (5) | 1.2% | — | ZEN Help Desk Software ZEN Help Desk | 11/6/2007 | 16/6/2026 | Zen Help Desk 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing a password via a direct request for ZenHelpDesk.mdb. | |
| Modificada | Alta (9.3) | 5.2% | — | BT Business Connect Webhelper Activex Control | 1/6/2007 | 16/6/2026 | Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Adobe RobohelpAdobe Robohelp Server | 10/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe RoboHelp X5, 6, and Server 6 allows remote attackers to inject arbitrary web script or HTML via a URL after a # (hash) in the URL path, as demonstrated using en/frameset-7.html, and possibly other unspecified vectors involving templates and (1) whstart.js and (2)… | |
| Modificada | Media (6.8) | 3.1% | — | Microgaming Download Helper Activex Control | 24/4/2007 | 16/6/2026 | Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Microsoft Html Help Workshop | 23/1/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Microsoft Html Help Workshop | 19/1/2007 | 16/6/2026 | Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a crafted .cnt file composed of lines that begin with an integer followed by a space and a long string. | |
| Modificada | Media (6.8) | 1.3% | — | Drupal Help TIP Module | 14/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles. | |
| Modificada | Alta (7.5) | 1.2% | — | Drupal Help TIP Module | 14/12/2006 | 16/6/2026 | SQL injection vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Ultimate Helpdesk | 7/12/2006 | 16/6/2026 | Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Ultimate Helpdesk | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Cerberus Helpdesk | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to inject arbitrary web script or HTML via the js parameter. NOTE: The provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (5) | 1.2% | — | Apple BomarchivehelperApple MAC OS XApple MAC OS X Server | 7/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in BOMArchiveHelper in Mac OS X allow user-assisted remote attackers to cause a denial of service (application crash) via unspecified vectors related to (1) certain KERN_PROTECTION_FAILURE thread crashes and (2) certain KERN_INVALID_ADDRESS thread crashes, as discovered with the… | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | ACE HelpdeskInverseflow Help DeskPmos Helpdesk | 28/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Doug Luxem Liberum Help Desk | 28/11/2006 | 16/6/2026 | SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Doug Luxem Liberum Help Desk | 28/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The provenance of this information is unknown; the details… | |
| Modificada | Baja (2.6) | 80% | 💥 Exploit | Microsoft Windows NT Helper ComponentsMicrosoft Windows XP | 31/10/2006 | 16/6/2026 | Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference. | |
| Modificada | Alta (7.5) | 1.8% | — | Oneorzero Helpdesk | 24/10/2006 | 16/6/2026 | The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Cerberus Helpdesk | 20/10/2006 | 16/6/2026 | rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request. | |
| Modificada | Alta (7.5) | 1.8% | — | Cerberus Helpdesk | 5/9/2006 | 16/6/2026 | (1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of… | |
| Modificada | Alta (7.6) | 20% | 💥 Exploit | Microsoft Help File Viewer | 14/8/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Turnkey WEB Tools PHP Live Helper | 10/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Mamboxchange A6mambohelpdesk | 31/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. |