Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Wpmanageninja Fluent SupportAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
AplazadaCrítica (9.8)0.95%—Customer Support Ticket System HelpdeskAI23/7/202623/7/2026
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated…
AnalizadaMedia (5.4)0.23%—Oracle Isupport21/7/202619/8/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Call Back). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability…
AnalizadaAlta (8.1)0.36%—Oracle Customer Support21/7/20266/8/2026
Vulnerability in the Oracle Customer Support product of Oracle E-Business Suite (component: Update Service Request). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Support. Successful…
AnalizadaAlta (7.4)0.32%—Oracle Isupport21/7/202631/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require…
AnalizadaMedia (6.6)0.38%—Oracle Isupport21/7/202631/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this…
AnalizadaMedia (6.6)0.38%—Oracle Isupport21/7/202630/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this…
AnalizadaAlta (7.7)0.35%—Oracle Isupport21/7/202630/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in…
AnalizadaAlta (7.4)0.34%—Oracle Isupport21/7/202630/7/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this…
AplazadaMedia (5.3)0.26%—Perfect Support Ticketing & Document Management SystemAI16/7/202616/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization checks. Attackers can add or remove any user,…
AplazadaMedia (5.1)0.24%—Perfect Support Ticketing AND Document Management SystemAI16/7/202618/7/2026
Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can store malicious scripts that execute in…
AplazadaMedia (6.5)0.22%—SupportcandyAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.
AplazadaMedia (6.5)0.59%—Majesticsupport Majestic SupportAI11/7/202613/7/2026
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaMedia (5.3)0.32%—Wpsupportplus WP Support Plus Responsive Ticket SystemAI9/7/20269/7/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.
AnalizadaAlta (8.5)0.53%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources…
AnalizadaAlta (8.7)0.65%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance…
AnalizadaCrítica (9.2)0.75%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated…
AnalizadaCrítica (9.2)0.46%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts…
AplazadaAlta (8.6)0.45%—Wpsupportplus WP Support Plus Responsive Ticket SystemAI30/6/202630/6/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (8.8)0.51%—Wpsupportplus Responsive Ticket SystemAI30/6/202630/6/2026
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site…
AplazadaMedia (4.4)0.34%—Team Members Multi Language Supported Team PluginAI30/6/202630/6/2026
The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
AplazadaMedia (5.4)0.23%—Majesticsupport Majestic SupportAI26/6/202626/6/2026
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
AplazadaAlta (7.6)0.31%—SupportcandyAI26/6/202629/6/2026
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
AplazadaCrítica (9.8)0.48%—Schiocco Support BoardAI17/6/202617/6/2026
Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.
AplazadaCrítica (9.8)0.45%—Support Ticket Management SystemAI17/6/20265/10/2026
Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.