Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.44% | — | Sysaid Application Programming Interface | 14/12/2021 | 17/6/2026 | Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names from the LDAP server. | |
| Modificada | Media (6.1) | 4.0% | — | Sysaid | 29/10/2021 | 17/6/2026 | SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication. | |
| Modificada | Alta (8.8) | 1.0% | — | Sysaid | 22/7/2021 | 17/6/2026 | SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or AssetManagementSummary.jsp (GET group1). | |
| Modificada | Media (6.1) | 2.5% | — | Sysaid | 22/7/2021 | 17/6/2026 | SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI. | |
| Modificada | Media (6.1) | 0.97% | — | Sysaid On-premisesSysaidsy On-premises | 2/10/2020 | 17/6/2026 | SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter. | |
| Modificada | Crítica (9.8) | 3.3% | — | Sysaid On-premise | 21/4/2020 | 17/6/2026 | SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This may be a duplicate of CVE-2020-1938 | |
| Modificada | Media (5) | 6.8% | — | Sysaid | 8/6/2015 | 17/6/2026 | SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password. | |
| Modificada | Alta (7.8) | 8.0% | — | Sysaid | 8/6/2015 | 17/6/2026 | SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2) /rdsmonitoringresponse, or (3) /androidactions, aka an XML Entity Expansion (XEE) attack. | |
| Modificada | Media (6.5) | 1.8% | — | Sysaid | 8/6/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report or an (3) ActiveRequests report to… | |
| Modificada | Media (5) | 26% | — | Sysaid | 8/6/2015 | 17/6/2026 | SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database password in WEB-INF/conf/serverConf.xml. | |
| Modificada | Media (5) | 57% | — | Sysaid | 8/6/2015 | 17/6/2026 | SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message. | |
| Modificada | Alta (8.5) | 87% | — | Sysaid | 8/6/2015 | 17/6/2026 | Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to… | |
| Modificada | Media (6.8) | 34% | — | Sysaid | 8/6/2015 | 17/6/2026 | The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byte after the extension, as demonstrated by a .war%00 file. | |
| Modificada | Media (6.5) | 50% | — | Sysaid | 8/6/2015 | 17/6/2026 | Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/. | |
| Modificada | Alta (7.5) | 55% | — | Sysaid | 8/6/2015 | 17/6/2026 | SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry. | |
| Modificada | Media (5) | 6.9% | — | Sysaid | 2/1/2015 | 17/6/2026 | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile. | |
| Modificada | Media (4.3) | 1.0% | — | Ilient Sysaid | 13/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SystemList.jsp in SysAid 5.1.08 allows remote attackers to inject arbitrary web script or HTML via the searchField parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.52% | — | Ilient Sysaid | 6/10/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Ilient SysAid 4.5.03 and 4.5.04 allows remote attackers to perform some actions as administrators, as demonstrated by changing the administrator password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |