Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)1.3%💥 ExploitJshelpdesk JS Help DeskAI4/3/202617/6/2026
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of…
AplazadaMedia (6.5)0.26%—Elextensions Elex Wordpress Helpdesk Customer Support Ticket SystemAI20/2/202617/6/2026
Missing Authorization vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.3.5.
AplazadaAlta (8.2)0.28%—Villatheme Happy Helpdesk Support Ticket SystemAI20/2/202617/6/2026
Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.8.
AplazadaMedia (5.3)0.30%—Elex Wordpress Helpdesk Customer Ticketing SystemAI5/2/202617/6/2026
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This…
AplazadaMedia (5.1)0.17%—Maian Support HelpdeskAI3/2/202617/6/2026
Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.
AplazadaMedia (4.3)0.16%—Helpdesk Contact FormAI7/1/202617/6/2026
The HelpDesk contact form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5. This is due to missing or incorrect nonce validation on the handle_query_args() function. This makes it possible for unauthenticated attackers to update the plugin's license ID and…
AplazadaMedia (5.3)0.22%—Villatheme Happy Helpdesk Support Ticket SystemAI23/12/202517/6/2026
Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.9.
AplazadaAlta (7.2)0.23%—Elex Wordpress Helpdesk Customer Ticketing SystemAI21/12/202528/9/2026
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AnalizadaAlta (8.6)0.56%—Frappe Helpdesk9/12/202517/6/2026
SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled parameters into dynamic SQL statements.This issue affects Frappe HelpDesk: 1.14.0.
AplazadaCrítica (10)0.45%—Villatheme Happy Helpdesk Support Ticket SystemAI6/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Remote Code Inclusion.This issue affects HAPPY: from n/a through <= 1.0.7.
AplazadaMedia (4.3)0.25%—Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI22/9/20251/10/2026
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1.
AplazadaMedia (6.5)0.23%—Villatheme Happy Helpdesk Support Ticket SystemAI5/9/202517/6/2026
Missing Authorization vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticket-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HAPPY: from n/a through <= 1.0.6.
AplazadaAlta (8.1)0.71%—Wordpress Helpdesk IntegrationAI5/9/202525/9/2026
The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.8.10 via the portal_type parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP…
AnalizadaMedia (4.4)0.21%—Django-helpdesk Project Django-helpdesk31/5/202517/6/2026
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
AplazadaMedia (6.5)0.27%—Vision HelpdeskAI15/4/202517/6/2026
Vision Helpdesk through 5.7.0 allows Time-Based Blind SQL injection via the Forgot Password (aka index.php?/home/forgot-password) vis_username parameter. Authentication is not needed.
AplazadaAlta (7.1)0.29%—M. ALI Saleem Support Helpdesk Ticket System LiteAI3/4/20256/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2.
AnalizadaAlta (7.7)0.31%—Qnap Helpdesk7/3/202517/6/2026
An improper certificate validation vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: Helpdesk 3.3.3 and later
AnalizadaMedia (4.8)0.27%—Helpdeskz26/2/202517/6/2026
A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.
AplazadaMedia (4.3)0.42%—Jshelpdesk THE Ultimate Help Desk AND Support PluginAI4/2/202517/6/2026
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.4)0.17%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.
AnalizadaMedia (6.1)0.23%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.
AnalizadaAlta (7.5)0.97%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Navigator/Index function.
AnalizadaAlta (8.1)0.33%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can delete admin users by sending a request to the "WSCView/Delete" function.
AnalizadaMedia (6.1)0.28%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the WSCView/Save function.
AnalizadaMedia (6.5)0.70%—Zucchetti Helpdeskadvanced13/1/202517/6/2026
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal. Arbitrary files can be created on the system via authenticated SOAP requests to the WSConnector service.
Orbitaley — Vulnerabilidades