Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—Kyberna Ky2help13/7/200616/6/2026
SQL injection vulnerability in Meine Links (aka My Links) in Kyberna ky2help allows remote authenticated users to execute arbitrary SQL commands via unspecified "textboxes."
ModificadaMedia (4.3)2.0%—Vanillasoft Helpdesk13/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in default.asp in VanillaSoft Helpdesk 2005 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaMedia (5.8)1.3%—Turnkey WEB Tools PHP Live Helper16/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter.
ModificadaAlta (7.5)1.2%—Ubertec Help Center Live26/4/200616/6/2026
Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaAlta (7.5)4.8%—Turnkey WEB Tools PHP Live Helper29/3/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php.
ModificadaAlta (7.5)2.0%—Turnkey WEB Tools PHP Live Helper29/3/200616/6/2026
Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by…
ModificadaAlta (7.5)72%💥 ExploitMicrosoft Html HelpMicrosoft Html Help Workshop6/2/200616/6/2026
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file field.
ModificadaMedia (4.3)2.0%💥 ExploitCerberus Helpdesk1/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
ModificadaAlta (7.5)1.1%—Help Desk Point Software Helpdeskpoint31/12/200516/6/2026
SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaAlta (7.5)3.2%💥 ExploitCerberus Helpdesk20/12/200516/6/2026
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to…
ModificadaMedia (4.3)1.3%—Cerberus Helpdesk20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.
ModificadaMedia (4.3)1.7%💥 ExploitNetauctionhelp7/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.
ModificadaAlta (7.5)1.4%—Help Desk Reloaded Free Help DeskAI5/12/200516/6/2026
Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.
ModificadaAlta (7.5)1.3%💥 ExploitHelpdesk Issue Manager30/11/200516/6/2026
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
ModificadaAlta (7.5)1.2%💥 ExploitEZY Helpdesk Ezyhelpdesk26/11/200516/6/2026
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
ModificadaAlta (7.5)2.8%💥 ExploitUbertec Help Center Live16/11/200516/6/2026
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.
ModificadaMedia (5)1.5%—Cerberus Helpdesk5/11/200516/6/2026
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
ModificadaAlta (7.5)3.0%💥 ExploitHelpdesk Software Hesk21/9/200516/6/2026
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.
ModificadaAlta (7.5)1.6%—Helpdesk Software Hesk8/9/200516/6/2026
Helpdesk software Hesk 0.92 does not properly verify usernames and passwords, which allows remote attackers to bypass authentication via a direct request to admin_main.php.
ModificadaMedia (4.3)1.3%—Cerberus Helpdesk16/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.
ModificadaMedia (5)1.5%—Cerberus Helpdesk16/6/200516/6/2026
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
ModificadaAlta (7.5)1.3%—Liberum Help Desk2/6/200516/6/2026
Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp.
ModificadaMedia (5)1.1%—Liberum Help Desk2/6/200516/6/2026
Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields.
ModificadaMedia (4.3)2.7%💥 ExploitUbertec Help Center Live19/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.
ModificadaMedia (6.5)2.9%💥 ExploitHelpcenterlive Help Center Live19/5/200516/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php.
Orbitaley — Vulnerabilidades