Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.63% | — | Getawesomesupport Awesome Support | 10/2/2024 | 17/6/2026 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Alta (8.8) | 0.22% | — | Getawesomesupport Awesome Support | 5/1/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5. | |
| Modificada | Alta (8.8) | 0.25% | — | Getawesomesupport Awesome Support | 30/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4. | |
| Modificada | Alta (8.1) | 0.66% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server. | |
| Modificada | Media (6.1) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.3) | 0.40% | — | Getawesomesupport Awesome Support | 6/11/2023 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission. | |
| Modificada | Media (5.4) | 0.39% | — | Wponlinesupport WP Responsive Header Image Slider | 3/10/2023 | 17/6/2026 | The WP Responsive header image slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'sp_responsiveslider' shortcode in versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers… | |
| Modificada | Alta (7.5) | 1.7% | — | Activesupport Project Activesupport | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a… | |
| Modificada | Media (6.5) | 0.75% | — | Getawesomesupport Awesome Support | 28/11/2022 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector | |
| Modificada | Media (5.4) | 0.57% | — | Getawesomesupport Awesome Support | 21/9/2022 | 17/6/2026 | Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress. | |
| Modificada | Alta (8.8) | 0.65% | — | Livesupporti Free Live Chat Support | 18/7/2022 | 17/6/2026 | The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.0.11. This is due to missing nonce protection on the livesupporti_settings() function found in the ~/livesupporti.php file. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (5.4) | 0.56% | — | Getawesomesupport Awesome Support | 26/11/2021 | 17/6/2026 | Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee). | |
| Modificada | Media (4.8) | 0.72% | — | Getawesomesupport Awesome Support | 9/1/2020 | 17/6/2026 | The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. | |
| Modificada | Media (6.1) | 0.91% | — | Getawesomesupport Awesome Support | 20/8/2019 | 17/6/2026 | The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages. | |
| Modificada | Crítica (9.8) | 6.1% | — | Activesupport Project Activesupport | 10/8/2018 | 17/6/2026 | active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Modificada | Alta (7.5) | 0.97% | — | Kayako Esupport | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action. | |
| Modificada | Alta (7.5) | 1.0% | — | Kayako Esupport | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action. | |
| Modificada | Alta (7.5) | 0.99% | — | Phplivesupport PHP Live! | 26/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x parameter to (1) message_box.php and (2) request.php. | |
| Modificada | Baja (3.5) | 1.0% | — | Kayako EsupportKayako Supportsuite | 28/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are… | |
| Modificada | Media (4.3) | 1.1% | — | Kayako EsupportKayako Supportsuite | 6/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules/tickets/functions_ticketsui.php in Kayako SupportSuite and eSupport 3.60.04 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the staff control panel, a different vector than CVE-2007-1145. | |
| Modificada | Alta (7.5) | 0.92% | — | Phplivesupport. Phplive! | 3/9/2009 | 16/6/2026 | SQL injection vulnerability in message_box.php in OSI Codes PHP Live! 3.3 allows remote attackers to execute arbitrary SQL commands via the deptid parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Kayako Esupport | 28/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.20.2 allows remote attackers to inject arbitrary web script or HTML via the jsMakeSrc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (4.3) | 2.3% | — | HP Esupportdiagnostics | 21/12/2007 | 16/6/2026 | HP eSupportDiagnostics ActiveX control (hpediag.dll) 1.0.11.0 exports dangerous methods, which allows remote attackers to (1) read arbitrary files via the ReadTextFile method, or (2) read arbitrary registry values via the ReadValue method. | |
| Modificada | Media (4.3) | 1.0% | — | Kayako Esupport | 9/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 3.00.90 allows remote attackers to inject arbitrary web script or HTML via the _m parameter. |