Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
516 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.28% | — | Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI | 15/6/2026 | 17/6/2026 | Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons <= 1.4.8 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Elex Wordpress Helpdesk & Customer Ticketing SystemAI | 15/6/2026 | 17/6/2026 | Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Jshelpdesk JS Help DeskAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions. | |
| Analizada | Crítica (9.5) | 5.7% | ⚠ Explotación activa | Simple-help Simplehelp | 12/6/2026 | 30/6/2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a… | |
| Aplazada | Media (5.3) | 0.47% | — | Helpfulcrowd Product ReviewsAI | 9/6/2026 | 23/7/2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is due to the `helpfulcrowd_validate_token()` function using a loose comparison operator (`!=`) instead of a strict comparison (`!==`) when validating the… | |
| Analizada | Alta (7.5) | 0.71% | — | Solarwinds WEB Help Desk | 2/6/2026 | 22/7/2026 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory. | |
| Aplazada | Media (6.5) | 0.39% | — | Enable Jquery Migrate HelperAI | 27/5/2026 | 17/6/2026 | The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function in all versions up to, and including, 1.4.1. This is due to the function only verifying a nonce without checking user capabilities.… | |
| Aplazada | Alta (8.1) | 0.38% | — | Livehelperchat Live Helper ChatAI | 14/5/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash… | |
| Pendiente de análisis | Alta (8.4) | 0.66% | — | Jupyter NotebookAIJupyterlabAIJupyter Help-extensionAIJupyterlab Help-extensionAI | 6/5/2026 | 17/6/2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook… | |
| Aplazada | Alta (8.7) | 0.38% | — | Oracle MCP Server Helper ToolAI | 5/5/2026 | 17/6/2026 | Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool.… | |
| Analizada | Media (4.8) | 0.26% | — | Helpy.io Helpy | 29/4/2026 | 17/6/2026 | Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated attacker with admin or agent editor privileges can persist arbitrary HTML or JavaScript in the body field of a knowledge base Doc.This issue affects helpy: 2.8.0. | |
| Analizada | Media (5.1) | 0.26% | — | Helpy.io Helpy | 29/4/2026 | 17/6/2026 | Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can persist arbitrary HTML in their account name field and cause it to be rendered unescaped in public forum threads where they participate, in the admin ticket view, and in HTML notification emails sent to… | |
| Analizada | Media (6.4) | 0.15% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in… | |
| Analizada | Media (5.1) | 0.14% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into the report title field when creating or editing a report, and the… | |
| Analizada | Media (5.1) | 0.14% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can inject arbitrary… | |
| Analizada | Media (4.8) | 0.15% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An authenticated… | |
| Analizada | Media (4.8) | 0.15% | — | GFI Helpdesk | 20/4/2026 | 17/6/2026 | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inject malicious… | |
| Pendiente de análisis | Media (4.3) | 0.17% | — | Vision HelpdeskAI | 16/4/2026 | 17/6/2026 | Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id. | |
| Analizada | Media (6.9) | 0.23% | — | Hainsoft Lanhelper | 5/4/2026 | 24/7/2026 | LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service condition. | |
| Aplazada | Alta (7.5) | 0.30% | — | Jshelpdesk JS Help DeskAI | 26/3/2026 | 17/6/2026 | The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing… | |
| Aplazada | Media (6.5) | 0.27% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (8.5) | 0.36% | — | Joomsky JS Help DeskAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.3. | |
| Aplazada | Alta (7.5) | 0.37% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2. | |
| Analizada | Media (6.8) | 0.42% | — | Uvnc Pchelpwarev2 | 21/3/2026 | 17/6/2026 | PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Group field. Attackers can paste a buffer overflow payload into the Group property field and click Ok to trigger an application crash. |